하나의 계정에 다수 출발지가 시도하는 공격을 탐지합니다.
개요
| 중요도 | 상 |
|---|---|
| 유형 | 배치 탐지 |
| 실행 주기 | 매달/매일/매시/0분 0 * * * * |
| 메시지 | VPN 동일 계정 다수 출발지 인증 실패: $account (출발지 $ip_cnt개 / $total회) |
| 출력 필드 순서 | account, ip_cnt, total, _time, src_ip, src_country, description, line |
| MITRE 기술 | T1110 |
| MITRE 전술 | TA0006 Credential Access |
| 출처 | 사용자 제안 |
쿼리
1table from=$("from") to=$("to") *:FW_PALOALTO
2| search _schema == "paloalto-ngfw-system" and event_id == "auth-fail"
3| rex field=description "for user '(?<account>[^']+)'"
4| rex field=description "From: (?<src_ip_str>\d+\.\d+\.\d+\.\d+)"
5| stats count as total, dc(src_ip_str) as ip_cnt by account
6| search ip_cnt >= 5
7| sort -ip_cnt
8| join type=left account [
9 table from=$("from") to=$("to") *:FW_PALOALTO
10 | search _schema == "paloalto-ngfw-system" and event_id == "auth-fail"
11 | rex field=description "for user '(?<account>[^']+)'"
12 | rex field=description "From: (?<src_ip_str>\d+\.\d+\.\d+\.\d+)"
13 | eval src_ip = ip(src_ip_str)
14 | lookup geoip src_ip output country as src_country
15]
16| order account, ip_cnt, total, _time, src_ip, src_country, description, line