Techniques
Sample rules
Prohibited Network Traffic Allowed
- source: splunk
- technicques:
Description
The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the “lookup_interesting_ports” table, is allowed. It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies. This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration. If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization’s security posture.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
values(All_Traffic.src_port) as src_port
values(All_Traffic.action) as action
values(All_Traffic.rule) as rule
FROM datamodel=Network_Traffic WHERE
All_Traffic.action IN ("allowed", "allow")
[
| inputlookup interesting_ports_lookup where is_prohibited="true"
| table dest_port transport
| dedup dest_port transport
| rename dest_port as All_Traffic.dest_port
| rename transport as All_Traffic.transport
]
by All_Traffic.src_ip All_Traffic.dest_ip
All_Traffic.dest_port All_Traffic.dvc
All_Traffic.transport All_Traffic.vendor_product
| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `drop_dm_object_name("All_Traffic")`
| `prohibited_network_traffic_allowed_filter`