Repository navigation
Conversation
| Ingest AWS CloudTrail management events into Splunk using the | ||
| aws:cloudtrail sourcetype. Ensure that successful EC2 Instance Connect | ||
| SendSSHPublicKey events are collected. Schedule the analytic with a short | ||
| lookback window appropriate for the environment, such as 10 minutes, and |
There was a problem hiding this comment.
minor update needed to how to implement to make it generic like other aws_cloudtrail detections.
….yml updating "how to implement" section
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9e04e6de5d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| values(vendor_region) as vendor_region | ||
| earliest(_time) as firstTime | ||
| latest(_time) as lastTime | ||
| by user |
There was a problem hiding this comment.
Keep AWS account context in the aggregation
In a central CloudTrail index that collects multiple AWS accounts, user_name is not globally unique. Because the preceding coalesce prefers that short name and this aggregation groups only by user, calls made by identically named users such as admin in different accounts are combined and can incorrectly cross the 10-event threshold as a “single identity.” Group by vendor_account as well, or use an account-qualified identity as the grouping key.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
@codex - what about using user_arn in the by clause, would that be better?
There was a problem hiding this comment.
not sure why it didnt reason the above comment but I think user_arn should be good
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9e04e6de5d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| search: |- | ||
| `cloudtrail` eventSource="ec2-instance-connect.amazonaws.com" eventName="SendSSHPublicKey" responseElements.success=true | ||
| | eval user=coalesce(user_name, 'userIdentity.arn', 'userIdentity.principalId') | ||
| | stats count as event_count |
There was a problem hiding this comment.
Deduplicate CloudTrail events before applying the threshold
When the same CloudTrail event is ingested more than once—for example, through overlapping trails or duplicate collection paths—stats count treats every copy as a separate SSH-key upload, so fewer than 10 actual API calls can trigger this detection. CloudTrail supplies a stable eventID for identifying duplicate deliveries; count distinct eventID values (or deduplicate on it) before applying the threshold.
Useful? React with 👍 / 👎.
….yml Group EC2 key uploads by AWS identity and count unique API events
Adds an AWS CloudTrail behavioral detection for 10 or more successful EC2 Instance Connect SendSSHPublicKey calls by a single identity. The detection uses CIM-compatible fields and includes validated attack data and a passing unit test.