Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,11 @@ describe('ML - data recognizer', () => {
'nginx_ecs',
'sample_data_ecommerce',
'sample_data_weblogs',
'siem_auditbeat_ecs',
'siem_winlogbeat_ecs',
'siem_auditbeat',
'siem_auditbeat_auth',
'siem_packetbeat',
'siem_winlogbeat',
'siem_winlogbeat_auth',
];

// check all module IDs are the same as the list above
Expand Down
Original file line number Diff line number Diff line change
@@ -1,23 +1,14 @@
{
"id": "siem_auditbeat_ecs",
"id": "siem_auditbeat",
"title": "SIEM Auditbeat",
"description": "Detect suspicious logins and unusual processes in Auditbeat ECS data (beta)",
"description": "Detect suspicious network activity and unusual processes in Auditbeat data (beta)",
"type": "Auditbeat data",
"logoFile": "logo.json",
"defaultIndexPattern": "auditbeat-*",
"query": {
"bool" : {
"bool": {
"filter": [
{
"bool": {
"should" : [
{ "terms": { "event.action": [ "process_started", "executed" ] } },
{ "term": { "event.category": "authentication" }}
],
"minimum_should_match" : 1
}
},
{ "term": { "agent.type": "auditbeat" } }
{"term": {"agent.type": "auditbeat"}}
]
}
},
Expand All @@ -26,10 +17,6 @@
"id": "rare_process_by_host_linux_ecs",
"file": "rare_process_by_host_linux_ecs.json"
},
{
"id": "suspicious_login_activity_ecs",
"file": "suspicious_login_activity_ecs.json"
},
{
"id": "linux_anomalous_network_activity_ecs",
"file": "linux_anomalous_network_activity_ecs.json"
Expand Down Expand Up @@ -61,11 +48,6 @@
"file": "datafeed_rare_process_by_host_linux_ecs.json",
"job_id": "rare_process_by_host_linux_ecs"
},
{
"id": "datafeed-suspicious_login_activity_ecs",
"file": "datafeed_suspicious_login_activity_ecs.json",
"job_id": "suspicious_login_activity_ecs"
},
{
"id": "datafeed-linux_anomalous_network_activity_ecs",
"file": "datafeed_linux_anomalous_network_activity_ecs.json",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"query": {
"bool": {
"filter": [
{"term": {"event.action": "connected-to"}}
{"term": {"event.action": "connected-to"}},
{"term": {"agent.type": "auditbeat"}}
],
"must_not": [
{
Expand All @@ -15,7 +16,8 @@
{"term": {"destination.ip": "127.0.0.1"}},
{"term": {"destination.ip": "127.0.0.53"}},
{"term": {"destination.ip": "::1"}}
]
],
"minimum_should_match": 1
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"query": {
"bool": {
"filter": [
{"term": {"event.action": "connected-to"}}
{"term": {"event.action": "connected-to"}},
{"term": {"agent.type": "auditbeat"}}
],
"must_not": [
{
Expand All @@ -16,7 +17,8 @@
{"term": {"destination.ip":"127.0.0.1"}},
{"term": {"destination.ip":"::"}},
{"term": {"user.name_map.uid":"jenkins"}}
]
],
"minimum_should_match": 1
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"query": {
"bool": {
"filter": [
{"term": {"event.action": "bound-socket"}}
{"term": {"event.action": "bound-socket"}},
{"term": {"agent.type": "auditbeat"}}
],
"must_not": [
{
Expand All @@ -15,7 +16,8 @@
{"term": {"process.name": "dnsmasq"}},
{"term": {"process.name": "docker-proxy"}},
{"term": {"process.name": "rpcinfo"}}
]
],
"minimum_should_match": 1
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,8 @@
"bool":{
"filter": [
{"exists": {"field": "destination.ip"}},
{"terms": {"process.name": ["curl", "wget"]}}
{"terms": {"process.name": ["curl", "wget"]}},
{"term": {"agent.type": "auditbeat"}}
],
"must_not":[
{
Expand All @@ -16,7 +17,8 @@
{"term":{"destination.ip": "::1"}},
{"term":{"destination.ip": "127.0.0.1"}},
{"term":{"destination.ip":"169.254.169.254"}}
]
],
"minimum_should_match": 1
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"query": {
"bool": {
"filter": [
{"term": {"event.action": "executed"}}
{"terms": {"event.action": ["process_started", "executed"]}},
{"term": {"agent.type": "auditbeat"}}
],
"must_not": [
{
Expand All @@ -16,7 +17,8 @@
{"term": {"user.name": "jenkins-user"}},
{"term": {"user.name": "jenkins"}},
{"wildcard": {"process.name": {"wildcard": "jenkins*"}}}
]
],
"minimum_should_match": 1
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"query": {
"bool": {
"filter": [
{"term": {"event.action":"executed"}}
{"terms": {"event.action": ["process_started", "executed"]}},
{"term": {"agent.type":"auditbeat"}}
]
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@
"query": {
"bool": {
"filter": [
{ "terms": { "event.action": [ "process_started", "executed" ] } }
{"terms": {"event.action": ["process_started", "executed"]}},
{ "term": { "agent.type": "auditbeat" } }

]
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
"job_type": "anomaly_detector",
"description": "SIEM Auditbeat: Looks for unusual processes using the network which could indicate command-and-control, lateral movement, persistence, or data exfiltration activity (beta)",
"groups": [
"siem"
"siem",
"auditbeat",
"process"
],
"analysis_config": {
"bucket_span": "15m",
Expand All @@ -24,8 +26,7 @@
"model_memory_limit": "64mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
"job_type": "anomaly_detector",
"description": "SIEM Auditbeat: Looks for unusual destination port activity that could indicate command-and-control, persistence mechanism, or data exfiltration activity (beta)",
"groups": [
"siem"
"siem",
"auditbeat",
"network"
],
"analysis_config": {
"bucket_span": "15m",
Expand All @@ -24,8 +26,7 @@
"model_memory_limit": "32mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
{
"job_type": "anomaly_detector",
"groups": [
"siem"
"siem",
"auditbeat",
"network"
],
"description": "SIEM Auditbeat: Looks for unusual listening ports that could indicate execution of unauthorized services, backdoors, or persistence mechanisms (beta)",
"analysis_config": {
Expand All @@ -23,8 +25,7 @@
"model_memory_limit": "128mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
{
"job_type": "anomaly_detector",
"groups": [
"siem"
"siem",
"auditbeat",
"network"
],
"description": "SIEM Auditbeat: Looks for an unusual web URL request from a Linux instance. Curl and wget web request activity is very common but unusual web requests from a Linux server can sometimes be malware delivery or execution (beta)",
"analysis_config": {
Expand All @@ -23,8 +25,7 @@
"model_memory_limit": "32mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
"job_type": "anomaly_detector",
"description": "SIEM Auditbeat: Looks for processes that are unusual to all Linux hosts. Such unusual processes may indicate unauthorized services, malware, or persistence mechanisms (beta)",
"groups": [
"siem"
"siem",
"auditbeat",
"process"
],
"analysis_config": {
"bucket_span": "15m",
Expand All @@ -23,8 +25,7 @@
"model_memory_limit": "512mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
{
"job_type": "anomaly_detector",
"groups": [
"siem"
"siem",
"auditbeat",
"process"
],
"description": "SIEM Auditbeat: Rare and unusual users that are not normally active may indicate unauthorized changes or activity by an unauthorized user which may be credentialed access or lateral movement (beta)",
"analysis_config": {
Expand All @@ -23,8 +25,7 @@
"model_memory_limit": "32mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,11 @@
{
"job_type": "anomaly_detector",
"description": "SIEM Auditbeat: Detect unusually rare processes on Linux (beta)",
"groups": ["siem"],
"groups": [
"siem",
"auditbeat",
"process"
],
"analysis_config": {
"bucket_span": "15m",
"detectors": [
Expand All @@ -22,8 +26,7 @@
"model_memory_limit": "256mb"
},
"data_description": {
"time_field": "@timestamp",
"time_format": "epoch_ms"
"time_field": "@timestamp"
},
"custom_settings": {
"created_by": "ml-module-siem-auditbeat",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"icon": "securityAnalyticsApp"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"id": "siem_auditbeat_auth",
"title": "SIEM Auditbeat Authentication",
"description": "Detect suspicious authentication events in Auditbeat data (beta)",
"type": "Auditbeat data",
"logoFile": "logo.json",
"defaultIndexPattern": "auditbeat-*",
"query": {
"bool": {
"filter": [
{"term": {"event.category": "authentication"}},
{"term": {"agent.type": "auditbeat"}}
]
}
},
"jobs": [
{
"id": "suspicious_login_activity_ecs",
"file": "suspicious_login_activity_ecs.json"
}
],
"datafeeds": [
{
"id": "datafeed-suspicious_login_activity_ecs",
"file": "datafeed_suspicious_login_activity_ecs.json",
"job_id": "suspicious_login_activity_ecs"
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"job_id": "JOB_ID",
"indexes": [
"INDEX_PATTERN_NAME"
],
"query": {
"bool": {
"filter": [
{"term": { "event.category": "authentication" }},
{"term": { "agent.type": "auditbeat" }}
]
}
}
}
Loading