Skip to content

Commit 186061f

Browse files
author
Patrick Bareiss
committed
new detection
1 parent 899e0f4 commit 186061f

23 files changed

+86
-22
lines changed

detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,5 +60,5 @@ tests:
6060
- name: True Positive Test
6161
attack_data:
6262
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1185/aws_concurrent_sessions_from_different_ips/asl_ocsf_cloudtrail.json
63-
sourcetype: aws:cloudtrail:lake
63+
sourcetype: aws:asl
6464
source: aws_asl

detections/cloud/asl_aws_create_access_key.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,5 +50,5 @@ tests:
5050
- name: True Positive Test
5151
attack_data:
5252
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
53-
sourcetype: aws:cloudtrail:lake
53+
sourcetype: aws:asl
5454
source: aws_asl

detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,5 +56,5 @@ tests:
5656
- name: True Positive Test
5757
attack_data:
5858
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
59-
sourcetype: aws:cloudtrail:lake
59+
sourcetype: aws:asl
6060
source: aws_asl

detections/cloud/asl_aws_credential_access_getpassworddata.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,5 +61,5 @@ tests:
6161
- name: True Positive Test
6262
attack_data:
6363
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
64-
sourcetype: aws:cloudtrail:lake
64+
sourcetype: aws:asl
6565
source: aws_asl

detections/cloud/asl_aws_credential_access_rds_password_reset.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,5 +60,5 @@ tests:
6060
- name: True Positive Test
6161
attack_data:
6262
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
63-
sourcetype: aws:cloudtrail:lake
63+
sourcetype: aws:asl
6464
source: aws_asl

detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,5 +58,5 @@ tests:
5858
- name: True Positive Test
5959
attack_data:
6060
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
61-
sourcetype: aws:cloudtrail:lake
61+
sourcetype: aws:asl
6262
source: aws_asl

detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,4 +59,4 @@ tests:
5959
attack_data:
6060
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/asl_ocsf_cloudtrail.json
6161
source: aws_asl
62-
sourcetype: aws:cloudtrail:lake
62+
sourcetype: aws:asl

detections/cloud/asl_aws_defense_evasion_impair_security_services.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,5 +51,5 @@ tests:
5151
- name: True Positive Test
5252
attack_data:
5353
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
54-
sourcetype: aws:cloudtrail:lake
54+
sourcetype: aws:asl
5555
source: aws_asl

detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,5 +53,5 @@ tests:
5353
- name: True Positive Test
5454
attack_data:
5555
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
56-
sourcetype: aws:cloudtrail:lake
56+
sourcetype: aws:asl
5757
source: aws_asl

detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,5 +58,5 @@ tests:
5858
- name: True Positive Test
5959
attack_data:
6060
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
61-
sourcetype: aws:cloudtrail:lake
61+
sourcetype: aws:asl
6262
source: aws_asl

0 commit comments

Comments
 (0)