AWS IAM User Access Investigation Deprecated

Deprecated. Use `Cloud IAM User Access Investigation` instead. Investigate and respond to Cortex XSIAM alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment. The following alerts are supported for AWS environments. - Penetration testing tool attempt - Penetration testing tool activity - Suspicious API call from a Tor exit node This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage feedback on the quality and usability of the content to help us identify and fix issues, so we can continually improve the content.

Core · 15 tasks · 5 inputs · 0 outputs

Details

IDAWS IAM User Access Investigation
From Version6.6.0
Tasks15

README

Deprecated. Use Cloud IAM User Access Investigation instead. Investigate and respond to Cortex XSIAM alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS environments.

  • Penetration testing tool attempt
  • Penetration testing tool activity
  • Suspicious API call from a Tor exit node
    This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage feedback on the quality and usability of the content to help us identify and fix issues, so we can continually improve the content.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Handle False Positive Alerts
  • Enrichment for Verdict
  • AWS IAM User Access Investigation - Remediation

Integrations

  • CortexCoreIR

Scripts

This playbook does not use any scripts.

Commands

  • closeInvestigation
  • core-get-cloud-original-alerts

Playbook Inputs


Name Description Default Value Required
AutoDeleteProfile Whether to automatically delete the user login profile if it exists (True/False). False Optional
AutoBlockIP Whether to initiate block IP playbook automatically (True/False). False Optional
IndicatorTag The tag name for bad reputation IP addresses investigated in the incident.
Use this when the EDL service is configured to add indicators to block in PANW PAN-OS.
If the indicator verdict (Malicious/Bad) is used to add indicators to Cortex XSIAM EDL you don’t need to use the tag. Indicators are set as malicious, automatically in the incident.
  Optional
DAG This input determines whether Palo Alto Networks Panorama or Firewall Dynamic Address Groups are used.
Specify the Dynamic Address Group tag name for IP handling.
  Optional
ShouldCloseAutomatically Whether to close alerts automatically as a false positive (True/False).   Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


AWS IAM User Access Investigation

Inputs

  • AutoDeleteProfile — Whether to automatically delete the user login profile if it exists (True/False).
  • AutoBlockIP — Whether to initiate block IP playbook automatically (True/False).
  • IndicatorTag — The tag name for bad reputation IP addresses investigated in the incident. Use this when the EDL service is configured to add indicators to block in PANW PAN-OS. If the indicator verdict (Malicious/Bad) is used to add indicators to Cortex XSIAM EDL you don't need to use the tag. Indicators are set as malicious, automatically in the incident.
  • DAG — This input determines whether Palo Alto Networks Panorama or Firewall Dynamic Address Groups are used. Specify the Dynamic Address Group tag name for IP handling.
  • ShouldCloseAutomatically — Whether to close alerts automatically as a false positive (True/False).

Commands used

closeInvestigation core-get-cloud-original-alerts

Flowchart

False Positive True positive yes yes Start Start Remediation Remediation Done Done Manual decision making - true/false-positive alert Manual decision making - ... False Positive - Done False Positive - Done Enrichment Enrichment Verdict Verdict AWS IAM User Access Investigation - Remediation - AWS IAM User Access Investigation - Remediation AWS IAM User Access Inves... AWS IAM User Access Investiga... Close the alert and finish the investigation? Close the alert and finis... Close alert after remediation - closeInvestigation Close alert after remedia... closeInvestigation Enrichment for Verdict - Enrichment for Verdict Enrichment for Verdict Enrichment for Verdict Get cloud original alert - core-get-cloud-original-alerts Get cloud original alert core-get-cloud-original-alerts Handle False Positive Alerts - Handle False Positive Alerts Handle False Positive Alerts Handle False Positive Alerts Continue the investigation Continue the investigation Is it a suspicious or Tor IP? Is it a suspicious or Tor...
id: AWS IAM User Access Investigation
version: -1
contentitemexportablefields:
  contentitemfields: {}
name: AWS IAM User Access Investigation
description: "Deprecated. Use `Cloud IAM User Access Investigation` instead. Investigate and respond to Cortex XSIAM alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment. \nThe following alerts are supported for AWS environments.\n- Penetration testing tool attempt\n- Penetration testing tool activity\n- Suspicious API call from a Tor exit node\n This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage feedback on the quality and usability of the content to help us identify and fix issues, so we can continually improve the content.\n"
deprecated: true
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 40b4c735-392d-4c86-8ab3-6d49441a813d
    type: start
    task:
      id: 40b4c735-392d-4c86-8ab3-6d49441a813d
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "48"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": -70
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: c48a2862-f3e1-4dd3-89b7-8590f645298b
    type: title
    task:
      id: c48a2862-f3e1-4dd3-89b7-8590f645298b
      version: -1
      name: 'Remediation '
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "54"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 1090
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "19":
    id: "19"
    taskid: 1e498a1e-df55-4805-8fa9-973ba6554ac1
    type: title
    task:
      id: 1e498a1e-df55-4805-8fa9-973ba6554ac1
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 510,
          "y": 1750
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: f452a1bf-3fc3-40db-8d4a-1666372f6a82
    type: condition
    task:
      id: f452a1bf-3fc3-40db-8d4a-1666372f6a82
      version: -1
      name: Manual decision making - true/false-positive alert
      description: Based on the collected data investigation and the verdict established by the "Enrichment for Verdict" playbook, is this a true positive event?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      False Positive:
      - "64"
      True positive:
      - "8"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 920
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: 043b96c8-7870-4754-823d-3a0658690cf2
    type: title
    task:
      id: 043b96c8-7870-4754-823d-3a0658690cf2
      version: -1
      name: False Positive - Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "19"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -90,
          "y": 1610
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "48":
    id: "48"
    taskid: 99d6201c-337d-4da6-82a1-bcd06c48573b
    type: title
    task:
      id: 99d6201c-337d-4da6-82a1-bcd06c48573b
      version: -1
      name: Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "61"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 80
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "50":
    id: "50"
    taskid: cee3b559-fdae-4404-863c-39f9dd375566
    type: title
    task:
      id: cee3b559-fdae-4404-863c-39f9dd375566
      version: -1
      name: Verdict
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "66"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 600
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "54":
    id: "54"
    taskid: 65900bdd-a39d-4848-8edc-4a3026a5360c
    type: playbook
    task:
      id: 65900bdd-a39d-4848-8edc-4a3026a5360c
      version: -1
      name: AWS IAM User Access Investigation - Remediation
      description: "Investigate and respond to Cortex XSIAM alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment. \nThe following alerts are supported for AWS environments.\n- Penetration testing tool attempt\n- Penetration testing tool activity\n- Suspicious API call from a Tor exit node\n This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage feedback on the quality and usability of the content to help us identify and fix issues, sp we can continually improve content.\n"
      playbookName: AWS IAM User Access Investigation - Remediation
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "57"
    scriptarguments:
      AutoBlockIP:
        complex:
          root: inputs.AutoBlockIP
      AutoDeleteProfile:
        complex:
          root: inputs.AutoDeleteProfile
      DAG:
        complex:
          root: inputs.DAG
      IP:
        complex:
          root: alert
          accessor: hostip
      IndicatorTag:
        complex:
          root: inputs.IndicatorTag
      accessKeyId:
        complex:
          root: Core.OriginalAlert.event.identity_orig
          accessor: accessKeyId
      userName:
        complex:
          root: alert
          accessor: username
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 550,
          "y": 1240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "57":
    id: "57"
    taskid: 9bc32470-1e47-447a-8a0b-f41a4049394c
    type: condition
    task:
      id: 9bc32470-1e47-447a-8a0b-f41a4049394c
      version: -1
      name: Close the alert and finish the investigation?
      description: "Close the alert and finish the investigation?"
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "65"
      "yes":
      - "58"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 1410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "58":
    id: "58"
    taskid: 2c77b9cd-84ff-48cc-86cd-a3cb3f439314
    type: regular
    task:
      id: 2c77b9cd-84ff-48cc-86cd-a3cb3f439314
      version: -1
      name: Close alert after remediation
      description: commands.local.cmd.close.inv
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "19"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 780,
          "y": 1580
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "60":
    id: "60"
    taskid: fe3f84ca-6874-4450-85d7-4de28a71fd11
    type: playbook
    task:
      id: fe3f84ca-6874-4450-85d7-4de28a71fd11
      version: -1
      name: Enrichment for Verdict
      playbookName: Enrichment for Verdict
      type: playbook
      iscommand: false
      brand: ""
      description: 'This playbook checks prior alert closing reasons and performs enrichment and prevalence checks on different IOC types. It then returns the information needed to establish the alert''s verdict.'
    nexttasks:
      '#none#':
      - "50"
    scriptarguments:
      CloseReason:
        simple: Resolved - False Positive,Resolved - Duplicate Incident,Resolved - Known Issue
      Domain:
        complex:
          root: alert
          accessor: domainname
      FileSHA256:
        complex:
          root: alert
          accessor: initiatorsha256
      IP:
        complex:
          root: alert
          accessor: hostip
      URL:
        complex:
          root: alert
          accessor: url
      User:
        complex:
          root: alert
          accessor: username
      awsUser:
        complex:
          root: alert
          accessor: username
      query:
        simple: (hostip:${alert.hostip}) and alertsource:${alert.sourceBrand} and alertname:${alert.name}
      threshold:
        simple: "5"
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 550,
          "y": 420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "61":
    id: "61"
    taskid: 6c5bcd44-dde7-429a-8838-d0e78c895537
    type: regular
    task:
      id: 6c5bcd44-dde7-429a-8838-d0e78c895537
      version: -1
      name: Get cloud original alert
      description: Returns information about each alert ID.
      script: '|||core-get-cloud-original-alerts'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "60"
    scriptarguments:
      alert_ids:
        complex:
          root: alert
          accessor: id
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "64":
    id: "64"
    taskid: 8eded0e7-c70b-40a6-8515-6a3215682533
    type: playbook
    task:
      id: 8eded0e7-c70b-40a6-8515-6a3215682533
      version: -1
      name: Handle False Positive Alerts
      description: |
        This playbook handles false positive alerts.
      playbookName: Handle False Positive Alerts
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "22"
    scriptarguments:
      ShouldCloseAutomatically:
        complex:
          root: inputs.ShouldCloseAutomatically
      alertName:
        complex:
          root: alert
          accessor: name
      sourceIP:
        complex:
          root: alert
          accessor: hostip
      username:
        complex:
          root: alert
          accessor: username
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -90,
          "y": 1090
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "65":
    id: "65"
    taskid: 62cfaa81-81fb-4166-8f73-e3e903c5e3c5
    type: regular
    task:
      id: 62cfaa81-81fb-4166-8f73-e3e903c5e3c5
      version: -1
      name: Continue the investigation
      description: Continue the investigation.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 320,
          "y": 1580
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "66":
    id: "66"
    taskid: ac7a9b9c-0d3c-494a-8def-9884ca58aadf
    type: condition
    task:
      id: ac7a9b9c-0d3c-494a-8def-9884ca58aadf
      version: -1
      name: Is it a suspicious or Tor IP?
      description: Is it a suspicious or Tor IP?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "21"
      "yes":
      - "8"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: containsGeneral
          left:
            value:
              simple: alert.name
            iscontext: true
          right:
            value:
              simple: Suspicious API call from a Tor exit node
        - operator: isEqualString
          left:
            value:
              simple: IPVerdict
            iscontext: true
          right:
            value:
              simple: Suspicious
    view: |-
      {
        "position": {
          "x": 550,
          "y": 750
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "21_64_False Positive": 0.54,
      "21_8_True positive": 0.48,
      "57_58_yes": 0.82,
      "66_8_yes": 0.37
    },
    "paper": {
      "dimensions": {
        "height": 1885,
        "width": 1250,
        "x": -90,
        "y": -70
      }
    }
  }
inputs:
- key: AutoDeleteProfile
  value:
    simple: "False"
  required: false
  description: Whether to automatically delete the user login profile if it exists (True/False).
  playbookInputQuery:
- key: AutoBlockIP
  value:
    simple: "False"
  required: false
  description: 'Whether to initiate block IP playbook automatically (True/False). '
  playbookInputQuery:
- key: IndicatorTag
  value: {}
  required: false
  description: |-
    The tag name for bad reputation IP addresses investigated in the incident.
    Use this when the EDL service is configured to add indicators to block in PANW PAN-OS.
    If the indicator verdict (Malicious/Bad) is used to add indicators to Cortex XSIAM EDL you don't need to use the tag. Indicators are set as malicious, automatically in the incident.
  playbookInputQuery:
- key: DAG
  value: {}
  required: false
  description: |-
    This input determines whether Palo Alto Networks Panorama or Firewall Dynamic Address Groups are used.
    Specify the Dynamic Address Group tag name for IP handling.
  playbookInputQuery:
- key: ShouldCloseAutomatically
  value: {}
  required: false
  description: Whether to close alerts automatically as a false positive (True/False).
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.6.0
supportedModules:
- agentix
- cloud
- cloud_posture
- cloud_runtime_security
- edr
- xsiam