Skip to content

Commit d985dc1

Browse files
committed
upgrade detection with tests to production
1 parent 4a48646 commit d985dc1

26 files changed

+91
-87
lines changed

detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Abnormally High Number Of Cloud Infrastructure API Calls
22
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects a spike in the number of API calls made
99
to your cloud infrastructure by a user. It leverages cloud infrastructure logs and

detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Abnormally High Number Of Cloud Security Group API Calls
22
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects a spike in the number of API calls made
99
to cloud security groups by a user. It leverages data from the Change data model,

detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: ASL AWS New MFA Method Registered For User
22
id: 33ae0931-2a03-456b-b1d7-b016c5557fbd
3-
version: 9
4-
date: '2025-05-02'
3+
version: 10
4+
date: '2025-06-10'
55
author: Patrick Bareiss, Splunk
6-
status: experimental
6+
status: production
77
type: TTP
88
description: The following analytic identifies the registration of a new Multi-Factor
99
Authentication (MFA) method for an AWS account, as logged through Amazon Security

detections/cloud/circle_ci_disable_security_step.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Circle CI Disable Security Step
22
id: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97
3-
version: 5
4-
date: '2025-05-02'
3+
version: 6
4+
date: '2025-06-10'
55
author: Patrick Bareiss, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects the disablement of security steps in a
99
CircleCI pipeline. It leverages CircleCI logs, using field renaming, joining, and

detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud API Calls From Previously Unseen User Roles
22
id: 2181ad1f-1e73-4d0c-9780-e8880482a08f
3-
version: 5
4-
date: '2025-05-02'
3+
version: 6
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects cloud API calls executed by user roles
99
that have not previously run these commands. It leverages the Change data model

detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud Compute Instance Created By Previously Unseen User
22
id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-06-10'
55
author: Rico Valdez, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic identifies the creation of cloud compute instances
99
by users who have not previously created them. It leverages data from the Change

detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud Compute Instance Created In Previously Unused Region
22
id: fa4089e2-50e3-40f7-8469-d2cc1564ca59
3-
version: 5
4-
date: '2025-05-02'
3+
version: 6
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects the creation of a cloud compute instance
99
in a region that has not been previously used within the last hour. It leverages

detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud Compute Instance Created With Previously Unseen Image
22
id: bc24922d-987c-4645-b288-f8c73ec194c4
3-
version: 5
4-
date: '2025-05-02'
3+
version: 6
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects the creation of cloud compute instances
99
using previously unseen image IDs. It leverages cloud infrastructure logs to identify

detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud Compute Instance Created With Previously Unseen Instance Type
22
id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
3-
version: 5
4-
date: '2025-05-02'
3+
version: 6
4+
date: '2025-06-10'
55
author: David Dorsey, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic detects the creation of EC2 instances with previously
99
unseen instance types. It leverages Splunk's tstats command to analyze data from

detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Cloud Instance Modified By Previously Unseen User
22
id: 7fb15084-b14e-405a-bd61-a6de15a40722
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-06-10'
55
author: Rico Valdez, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: The following analytic identifies cloud instances being modified by users
99
who have not previously modified them. It leverages data from the Change data model,

0 commit comments

Comments
 (0)