LoFP LoFP / t1496

t1496

TitleTags
a dns lookup does not necessarily mean a successful attempt, verify a) if there was a response using the zeek answers field, if there was then verify the connections (conn.log) to those ips. b) verify if http, ssl, or tls activity to the domain that was queried. http.log field is 'host' and ssl/tls is 'server_name'.
a principal that legitimately both registers a high-compute public-image task definition and runs ecs workloads in the same window could match (for example, some data-science or batch pipelines). confirm the image and cpu in \"aws.cloudtrail.request_parameters\" of the registertaskdefinition event, the launched workload, and whether the principal in \"aws.cloudtrail.user_identity.arn\" is an expected ecs operator; exclude known principals after validation. the cpu threshold and registry list are tunable in the query.
clusterroles/roles being modified and deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
clusterroles/roles modification from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
container registry being created or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
container registry created or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
kubernetes cluster being created or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
kubernetes cluster created or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
legitimate crypto coin mining
legitimate high-throughput applications, batch jobs, load tests, and automation can invoke functions at high volume and will exceed any fixed threshold. validate the principal in `aws.cloudtrail.user_identity.arn` and the workload context, and tune the threshold to the environment.
legitimate use of crypto miners
legitimate users may create sns topics for legitimate purposes. ensure that the creation is authorized before taking action.
legitimate users may subscribe to sns topics for legitimate purposes. ensure that the subscription is authorized before taking action.
network policy being modified and deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
network policy being modified and deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
new users or roles may legitimately publish messages to sns topics for authorized purposes. ensure that the action is authorized before taking action.
provisioned throughput changes may be performed by platform, ml, or finops teams as part of capacity planning, scaling for production demand, or cost optimization. infrastructure-as-code pipelines and automation roles may also create, update, or delete provisioned throughput during deployments. verify that the user identity, user agent, and source ip correspond to known administrators or automation and that a corresponding change request exists. if known behavior is causing false positives, it can be exempted from the rule.
rolebinding/clusterrolebinding being modified and deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
rolebinding/clusterrolebinding modification from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
sensitive objects may be accessed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. sensitive objects accessed from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
service account being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
service account modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
some build frameworks
unlikely