Anvilogic high experimental spl
AWS SendSSHPublicKey [splunk-awscloudtrail]
SendSSHPublicKey pushes an SSH public key to the specified EC2 instance for use by the specified user. While this service is designed to enhance security by eliminating the need for permanent SSH keys, it can also be exploited by threat actors if not properly secured, leading to unauthorized access, persistence, privilege escalation, or lateral movement. This use case detection when SendSSHPublicKey is called.
Detection Logic
`get_cloud_data` `get_cloud_data_aws` TERM(SendSSHPublicKey)
| table _time, host, user, account, region, src_ip, http_user_agent, access_key, user, user_id, identity_type, role, event_name, event_category, cloud_service, request_parameters, response, mfa_enabled, permissions, identity, action, resource_id, object_id
| bin span=1s
| stats values(*) as * by _time, src_ip
| lookup dnslookup clientip as src_ip OUTPUT clienthost as src_dns
| iplocation prefix="src_" src_ip
| rename src_Country as src_country Field Validations
Loading…
Comments (0)
Loading comments...