하나의 계정에 다수 출발지가 시도하는 공격을 탐지합니다.
Overview
| Priority | High |
|---|---|
| Type | Batch |
| Schedule | Every month/Every day/Every hour/At 0 min 0 * * * * |
| Message | VPN 동일 계정 다수 출발지 인증 실패: $account (출발지 $ip_cnt개 / $total회) |
| Output field order | account, ip_cnt, total, _time, src_ip, src_country, description, line |
| MITRE Techniques | T1110 |
| MITRE tactics | TA0006 Credential Access |
| Origin | User proposal |
Query
1table from=$("from") to=$("to") *:FW_PALOALTO
2| search _schema == "paloalto-ngfw-system" and event_id == "auth-fail"
3| rex field=description "for user '(?<account>[^']+)'"
4| rex field=description "From: (?<src_ip_str>\d+\.\d+\.\d+\.\d+)"
5| stats count as total, dc(src_ip_str) as ip_cnt by account
6| search ip_cnt >= 5
7| sort -ip_cnt
8| join type=left account [
9 table from=$("from") to=$("to") *:FW_PALOALTO
10 | search _schema == "paloalto-ngfw-system" and event_id == "auth-fail"
11 | rex field=description "for user '(?<account>[^']+)'"
12 | rex field=description "From: (?<src_ip_str>\d+\.\d+\.\d+\.\d+)"
13 | eval src_ip = ip(src_ip_str)
14 | lookup geoip src_ip output country as src_country
15]
16| order account, ip_cnt, total, _time, src_ip, src_country, description, line