security_content
security_content copied to clipboard
Nterl0k [T1098] - O365 Azure Workload things
Details
This PR includes a number of detections written for the O365 Azure Active Directory workload from the universal audit log (o365 management activity). A few of the detections are 1:1 duplicates of existing ESCU content or expands coverage, only adapted for a slightly easier to access data source. Other detections are focused on monitoring sensitive changes to a number of Azure external access settings.
- O365 Privileged Role Assigned (duplicate Azure AD Privileged Role Assigned and O365 High Privilege Role Granted)
- O365 Privileged Role Assigned To Service Principal (duplicate -Azure AD Privileged Role Assigned to Service Principal)
- O365 External Guest User Invited (duplicate - Azure AD External Guest User Invited)
- O365 Cross-Tenant Access Change (New)
- O365 External Identity Policy Changed (New)
- O365 Application Available To Other Tenants (New)
These detections also extract either the User Principal or Service Principal from the Actor field. Recommend profile your azure environments to populate this data into Assets and Identities.
This PR also includes a number of changes to the "lookups/privileged_azure_ad_roles" lookup and lookup definition, mainly for the purpose of including more known privileged Azure groups relevant in 2024, none of the previous groups were removed.
An additional column has been added to also include the "Template ID" for all groups, which is an immutable GUID used by MS. This GUI should allow for more accurate detections if/when Microsoft changes the string values of well-known objects. (https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference)
Changes to lookup should be backward compatible with existing content.
pending data PR https://github.com/splunk/attack_data/pull/891
Checklist
- [ ] Validate name matches
<platform>_<mitre att&ck technique>_<short description>
nomenclature - [ ] CI/CD jobs passed ✔️
- [ ] Validated SPL logic.
- [ ] Validated tags, description, and how to implement.
- [ ] Verified references match analytic.