Anvilogic high experimental spl

AWS SendSSHPublicKey [splunk-awscloudtrail]

SendSSHPublicKey pushes an SSH public key to the specified EC2 instance for use by the specified user. While this service is designed to enhance security by eliminating the need for permanent SSH keys, it can also be exploited by threat actors if not properly secured, leading to unauthorized access, persistence, privilege escalation, or lateral movement. This use case detection when SendSSHPublicKey is called.

View Source

Detection Logic

`get_cloud_data` `get_cloud_data_aws` TERM(SendSSHPublicKey)
| table _time, host, user, account, region, src_ip, http_user_agent, access_key, user, user_id, identity_type, role, event_name, event_category, cloud_service, request_parameters, response, mfa_enabled, permissions, identity, action, resource_id, object_id
| bin span=1s
| stats values(*) as * by _time, src_ip
| lookup dnslookup clientip as src_ip OUTPUT clienthost as src_dns
| iplocation prefix="src_" src_ip
| rename src_Country as src_country

Field Validations

Loading…

Comments (0)

Loading comments...