Skip to content

Commit

Permalink
add new deployment functionality
Browse files Browse the repository at this point in the history
  • Loading branch information
P4T12ICK committed Jan 4, 2023
1 parent 5ae53c9 commit b352a14
Show file tree
Hide file tree
Showing 83 changed files with 204 additions and 310 deletions.
2 changes: 0 additions & 2 deletions baselines/baseline_of_blocked_outbound_traffic_from_aws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,6 @@ tags:
- AWS Network ACL Activity
- Suspicious AWS Traffic
- Command and Control
deployments:
- Daily Cache Updates
detections:
- Detect Spike in blocked Outbound Traffic from your AWS
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Infrastructure API Calls
product:
Expand All @@ -47,3 +45,9 @@ tags:
- All_Changes.user
- All_Changes.status
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
8 changes: 6 additions & 2 deletions baselines/baseline_of_cloud_instances_destroyed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,8 +37,6 @@ tags:
analytic_story:
- Suspicious Cloud Instance Activities
- Cloud Cryptomining
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Instances Destroyed
product:
Expand All @@ -51,3 +49,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
8 changes: 6 additions & 2 deletions baselines/baseline_of_cloud_instances_launched.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,8 +37,6 @@ tags:
analytic_story:
- Cloud Cryptomining
- Suspicious Cloud Instance Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Instances Launched
product:
Expand All @@ -51,3 +49,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Security Group API Calls
product:
Expand All @@ -47,3 +45,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
3 changes: 1 addition & 2 deletions baselines/baseline_of_command_line_length___mltk.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,6 @@ tags:
- Suspicious Command-Line Executions
- Suspicious MSHTA Activity
- Unusual Processes
deployments:
- Daily Cache Updates
detections:
- Detect Prohibited Applications Spawning cmd.exe
- Unusually Long Command Line - MLTK
Expand All @@ -50,3 +48,4 @@ tags:
- Processes.process_name
- Processes.process
security_domain: endpoint

2 changes: 0 additions & 2 deletions baselines/baseline_of_dns_query_length___mltk.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,6 @@ tags:
- Hidden Cobra Malware
- Suspicious DNS Traffic
- Command and Control
deployments:
- Daily Cache Updates
detections:
- DNS Query Length Outliers - MLTK
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/baseline_of_network_acl_activity_by_arn.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- AWS Network ACL Activity
deployments:
- Daily Cache Updates
detections:
- Detect Spike in Network ACL Activity
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/baseline_of_s3_bucket_deletion_activity_by_arn.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS S3 Activities
deployments:
- Daily Cache Updates
detections:
- Detect Spike in S3 Bucket deletion
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/baseline_of_security_group_activity_by_arn.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect Spike in Security Group Activity
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/baseline_of_smb_traffic___mltk.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,6 @@ tags:
- Hidden Cobra Malware
- Netsh Abuse
- Ransomware
deployments:
- Daily Cache Updates
detections:
- Processes launching netsh
- SMB Traffic Spike - MLTK
Expand Down
2 changes: 0 additions & 2 deletions baselines/count_of_assets_by_category.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,6 @@ references: []
tags:
analytic_story:
- Asset Tracking
deployments:
- Daily Cache Updates
detections:
- Detect Unauthorized Assets by MAC address
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/count_of_unique_ips_connecting_to_ports.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@ tags:
- Prohibited Traffic Allowed or Protocol Mismatch
- Ransomware
- Command and Control
deployments:
- Daily Cache Updates
detections:
- Prohibited Network Traffic Allowed
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/create_a_list_of_approved_aws_service_accounts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect AWS API Activities From Unapproved Accounts
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ tags:
- Monitor for Unauthorized Software
- SamSam Ransomware
asset_type: Endpoint
deployments:
- Daily Cache Updates
detections:
- Prohibited Software On Endpoint
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/deprecated/baseline_of_api_calls_per_user_arn.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect Spike in AWS API Activity
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- Abnormally High AWS Instances Launched by User - MLTK
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- Abnormally High AWS Instances Terminated by User - MLTK
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect new API calls from user roles
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@ references: []
tags:
analytic_story:
- AWS Suspicious Provisioning Activities
deployments:
- Daily Cache Updates
detections:
- AWS Cloud Provisioning From Previously Unseen IP Address
- AWS Cloud Provisioning From Previously Unseen City
Expand Down
2 changes: 0 additions & 2 deletions baselines/deprecated/previously_seen_ec2_amis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- AWS Cryptomining
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen AMI
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/deprecated/previously_seen_ec2_instance_types.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- AWS Cryptomining
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen Instance Type
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/deprecated/previously_seen_ec2_launches_by_user.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen User
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/deprecated/previously_seen_users_in_cloudtrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS Login Activities
deployments:
- Daily Cache Updates
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS Login Activities
deployments:
- Daily Cache Updates
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
Expand Down
2 changes: 0 additions & 2 deletions baselines/discover_dns_records.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,6 @@ references: []
tags:
analytic_story:
- DNS Hijacking
deployments:
- Daily Cache Updates
detections:
- DNS record changed
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/dnstwist_domain_names.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@ tags:
- Brand Monitoring
- Suspicious Emails
asset_type: Endpoint
deployments:
- Daily Cache Updates
detections:
- Monitor Email For Brand Abuse
- Monitor DNS For Brand Abuse
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/identify_systems_using_remote_desktop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/monitor_successful_backups.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- Monitor Backup Solution
deployments:
- Daily Cache Updates
detections:
- Unsuccessful Netbackup backups
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/monitor_unsuccessful_backups.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,6 @@ references: []
tags:
analytic_story:
- Monitor Backup Solution
deployments:
- Daily Cache Updates
detections:
- Unsuccessful Netbackup backups
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/previously_seen_aws_cross_account_activity.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS Cross Account Activity
deployments:
- Daily Cache Updates
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- 90 Day Baseline
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
Expand All @@ -42,3 +40,9 @@ tags:
- Authentication.src
- Authentication.user_role
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- Daily Cache Updates
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
Expand Down
2 changes: 0 additions & 2 deletions baselines/previously_seen_aws_regions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started In Previously Unseen Region
product:
Expand Down
Loading

0 comments on commit b352a14

Please sign in to comment.