Cloud Data Exfiltration Response

## Cloud Data Exfiltration Response The Cloud Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling "An identity performed a suspicious download of multiple cloud storage object" alert. The playbook supports AWS, GCP, and Azure and executes the following: - Enrichment involved assets. - Determines the appropriate verdict based on the data collected from the enrichment. - Cloud Persistence Threat Hunting: - Conducts threat hunting activities to identify any cloud persistence techniques - Verdict Handling: - Handles false positives identified during the investigation - Handles true positives by initiating appropriate response actions

Cloud Incident Response · 26 tasks · 7 inputs · 0 outputs

Details

IDCloud Data Exfiltration Response
From Version6.8.0
Tasks26

README

Cloud Data Exfiltration Response

The Cloud Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling “An identity performed a suspicious download of multiple cloud storage object” alert.
The playbook supports AWS, GCP, and Azure and executes the following:

  • Enrichment involved assets.
  • Determines the appropriate verdict based on the data collected from the enrichment.
  • Cloud Persistence Threat Hunting:
    • Conducts threat hunting activities to identify any cloud persistence techniques
  • Verdict Handling:
    • Handles false positives identified during the investigation
    • Handles true positives by initiating appropriate response actions

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Cloud User Investigation - Generic
  • Cloud Threat Hunting - Persistence
  • Handle False Positive Alerts
  • Cloud Credentials Rotation - Generic
  • Cloud Response - Generic

Integrations

This playbook does not use any integrations.

Scripts

  • SearchIncidentsV2

Commands

  • ip
  • closeInvestigation
  • core-get-cloud-original-alerts
  • core-get-IP-analytics-prevalence

Playbook Inputs


Name Description Default Value Required
autoUserRemediation Whether to execute the user remediation automatically. (Default: False) False Optional
autoBlockIndicators Whether to execute the block remediation automatically. (Default: False) False Optional
credentialsRemediationType The response playbook provides the following remediation actions using AWS, MSGraph Users, GCP and GSuite Admin:

Reset: By entering “Reset” in the input, the playbook will execute password reset.
Supports: AWS, MSGraph Users, GCP and GSuite Admin.

Revoke: By entering “Revoke” in the input, the GCP will revoke the access key, GSuite Admin will revoke the access token and the MSGraph Users will revoke the session.
Supports: GCP, GSuite Admin and MSGraph Users.

Deactivate - By entering “Deactivate” in the input, the playbook will execute access key deactivation.
Supports: AWS.

ALL: By entering “ALL” in the input, the playbook will execute the all remediation actions provided for each CSP.
Reset Optional
shouldCloneSA Whether to clone the compromised SA before putting a deny policy to it.
Supports: AWS.
True/False
False Optional
newInstanceProfileName The new instance profile name to assign in the clone service account flow.   Optional
AWS-newRoleName The new role name to assign in the clone service account flow.   Optional
AWS-roleNameToRestrict If provided, the role will be attached with a deny policy without the compute instance analysis flow.   Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Cloud Data Exfiltration Response

Inputs

  • autoUserRemediation — Whether to execute the user remediation automatically. (Default: False)
  • autoBlockIndicators — Whether to execute the block remediation automatically. (Default: False)
  • credentialsRemediationType — The response playbook provides the following remediation actions using AWS, MSGraph Users, GCP and GSuite Admin: Reset: By entering "Reset" in the input, the playbook will execute password reset. Supports: AWS, MSGraph Users, GCP and GSuite Admin. Revoke: By entering "Revoke" in the input, the GCP will revoke the access key, GSuite Admin will revoke the access token and the MSGraph Users will revoke the session. Supports: GCP, GSuite Admin and MSGraph Users. Deactivate - By entering "Deactivate" in the input, the playbook will execute access key deactivation. Supports: AWS. ALL: By entering "ALL" in the input, the playbook will execute the all remediation actions provided for each CSP.
  • shouldCloneSA — Whether to clone the compromised SA before putting a deny policy to it. Supports: AWS. True/False
  • AWS-newInstanceProfileName — The new instance profile name to assign in the clone service account flow.
  • AWS-newRoleName — The new role name to assign in the clone service account flow.
  • AWS-roleNameToRestrict — If provided, the role will be attached with a deny policy without the compute instance analysis flow.

Commands used

closeInvestigation core-get-IP-analytics-prevalence core-get-cloud-original-alerts ip

Flowchart

Malicious Finish Playbook No Yes yes yes Start Start Entity Enrichment Entity Enrichment Enumeration Alert Search Enumeration Alert Search Search alerts for cloud enumeration activity - SearchIncidentsV2 Search alerts for cloud e... SearchIncidentsV2 Check IP Prevelance Check IP Prevelance Enrichment Enrichment Done Done Close Alert - closeInvestigation Close Alert closeInvestigation Found malicious evidence based on enrichment data Found malicious evidence ... Review the alert findings Review the alert findings IP prevalence check - core-get-IP-analytics-prevalence IP prevalence check core-get-IP-analytics-prevalence Investigation Investigation Handle False Positive Alerts - Handle False Positive Alerts Handle False Positive Alerts Handle False Positive Alerts Threat Hunting Threat Hunting No Malicious activity identified No Malicious activity ide... Check IP Reputation - ip Check IP Reputation ip Found any persistence evidences or user abnormal activity? Found any persistence evi... Malicious Activity identified Malicious Activity identi... Get cloud extra data - core-get-cloud-original-alerts Get cloud extra data core-get-cloud-original-alerts Containment Plan Containment Plan Set Alert Verdict Set Alert Verdict Cloud Response - Generic - Cloud Response - Generic Cloud Response - Generic Cloud Response - Generic Cloud Threat Hunting - Persistence - Cloud Threat Hunting - Persistence Cloud Threat Hunting - Pe... Cloud Threat Hunting - Persis... Cloud User Investigation - Generic - Cloud User Investigation - Generic Cloud User Investigation ... Cloud User Investigation - Ge... Should rotate the credentials automatically? Should rotate the credent... Cloud Credentials Rotation - Generic - Cloud Credentials Rotation - Generic Cloud Credentials Rotatio... Cloud Credentials Rotation - ...
id: Cloud Data Exfiltration Response
version: -1
name: Cloud Data Exfiltration Response
description: "## Cloud Data Exfiltration Response\n\nThe Cloud Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling \"An identity performed a suspicious download of multiple cloud storage object\" alert.\nThe playbook supports AWS, GCP, and Azure and executes the following:\n- Enrichment involved assets. \n- Determines the appropriate verdict based on the data collected from the enrichment. \n- Cloud Persistence Threat Hunting:\n  - Conducts threat hunting activities to identify any cloud persistence techniques\n- Verdict Handling:\n  - Handles false positives identified during the investigation\n  - Handles true positives by initiating appropriate response actions"
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 22d468a7-b5b0-47bd-8376-e59f74fab8e1
    type: start
    task:
      id: 22d468a7-b5b0-47bd-8376-e59f74fab8e1
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "73"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": -120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 676a1dee-45cb-4f60-8e6a-125fa23d9e42
    type: title
    task:
      id: 676a1dee-45cb-4f60-8e6a-125fa23d9e42
      version: -1
      name: Entity Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "59"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1080,
          "y": 320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 3c7469d0-c6e8-4523-8440-2b90681d38a2
    type: title
    task:
      id: 3c7469d0-c6e8-4523-8440-2b90681d38a2
      version: -1
      name: Enumeration Alert Search
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "13"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 280,
          "y": 320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: 1bbbc703-b46d-4532-83c6-e51b27cf570d
    type: regular
    task:
      id: 1bbbc703-b46d-4532-83c6-e51b27cf570d
      version: -1
      name: Search alerts for cloud enumeration activity
      description: |-
        Searches Cortex XSIAM alerts. A summarized version of this scrips is available with the summarizedversion argument.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "78"
    scriptarguments:
      details:
        simple: '*enumeration*'
      fromdate:
        simple: 1 day ago
      query:
        complex:
          root: alert
          accessor: username
          transformers:
          - operator: FirstArrayElement
          - operator: uniq
          - operator: concat
            args:
              prefix:
                value:
                  simple: (mitre_tactic_id_and_name:"TA0007 - Discovery") and (actor_effective_username:"
              suffix:
                value:
                  simple: '")'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 280,
          "y": 460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 7edb2290-6dfc-4c91-899f-4a73b47ca242
    type: title
    task:
      id: 7edb2290-6dfc-4c91-899f-4a73b47ca242
      version: -1
      name: Check IP Prevelance
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "43"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: ef365d2c-9f1e-4d23-8c0d-370585b85f13
    type: title
    task:
      id: ef365d2c-9f1e-4d23-8c0d-370585b85f13
      version: -1
      name: Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "6"
      - "23"
      - "1"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "30":
    id: "30"
    taskid: 0bd1ea2c-e85f-4172-8763-772bfa9a3057
    type: title
    task:
      id: 0bd1ea2c-e85f-4172-8763-772bfa9a3057
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1260,
          "y": 2570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "31":
    id: "31"
    taskid: b2a335ad-2aaf-4e7a-8ccf-252137bebdd2
    type: regular
    task:
      id: b2a335ad-2aaf-4e7a-8ccf-252137bebdd2
      version: -1
      name: Close Alert
      description: commands.local.cmd.close.inv
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "30"
    scriptarguments:
      closeReason:
        simple: True Positive.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 930,
          "y": 2400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "32":
    id: "32"
    taskid: 9c4eb7f8-d21f-4ac7-83bc-167244ce5cb7
    type: condition
    task:
      id: 9c4eb7f8-d21f-4ac7-83bc-167244ce5cb7
      version: -1
      name: Found malicious evidence based on enrichment data
      description: "This step will check the following and if one of those conditions match, this alert is malicious/suspicious:\n\n- Is there access to a backup bucket? \n- Check IP prevalence - if the IP is a known IP in the company\n- Is the IP malicious?\n- Is there an enumeration alert associated with the same user?\n- Is the IP known as one of the organization VPN address?\n- Is there minimum access to this bucket? Will be determined by a threshold."
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "47"
      Malicious:
      - "64"
    separatecontext: false
    conditions:
    - label: Malicious
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: IP.Malicious
            iscontext: true
          right:
            value: {}
        - operator: containsGeneral
          left:
            value:
              simple: foundIncidents.details
            iscontext: true
          right:
            value:
              simple: enumeration
          ignorecase: true
        - operator: isEqualString
          left:
            value:
              complex:
                root: Core.OriginalAlert.event
                accessor: is_bucket_name_backup_storage
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
        - operator: isEqualString
          left:
            value:
              complex:
                root: Core.OriginalAlert.event
                accessor: is_caller_ip_organization_vpn_ip_address
            iscontext: true
          right:
            value:
              simple: "False"
          ignorecase: true
        - operator: lessThanOrEqual
          left:
            value:
              complex:
                root: Core.OriginalAlert.event
                accessor: cloud_provider_bucket_name_days_seen_count_bucket_object_download
            iscontext: true
          right:
            value:
              simple: "5"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 790
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: f5f819b3-f6eb-4f10-837e-c6a859a1cf42
    type: condition
    task:
      id: f5f819b3-f6eb-4f10-837e-c6a859a1cf42
      version: -1
      name: Review the alert findings
      description: "The enrichment process didn't identify any further suspicious activity.\nPlease review these alert findings and choose how to handle it.\n\nSuggested checklist for the analyst:\n- Check the environment of the bucket - Is it in QA / Dev / Alpha / Production? Is it should be publicly available?
- Check the information in the bucket - Is there any PII? Any configurations that might be potentially harmful in the wrong hands (such as API keys).\nDid you find this alert to be malicious/suspicious?\nIf you choose yes, the playbook will continue with containment actions\nNo will execute 'Handle False Positive' sub-playbook.\nFinish Playbook will end the playbook."
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      Finish Playbook:
      - "30"
      "No":
      - "51"
      "Yes":
      - "76"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1260,
          "y": 1730
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: |-
          The enrichment process didn't identify any further suspicious activity.
          Please review this alert findings and choose how to handle it.

          Suggested checklist for the analyst:
          - Check the environment of the bucket - Is it in QA / Dev / Alpha / Production? Is it should be publically available?
          - Check the information in the bucket - Is there any PII? Any configurations that might be potentially harmful in the wrong hands ( such as API keys).


          Did you find this alert to be malicious/suspicious?
          - If you choose yes, the playbook will continue with containment actions
          - No will execute 'Handle False Positive' sub-playbook.
          - Finish Playbook will end the playbook."
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
      replyOptions:
      - Yes
      - No
      - Finish Playbook
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "43":
    id: "43"
    taskid: 521b51bd-c579-4cf4-8d2e-aa8ad689b227
    type: regular
    task:
      id: 521b51bd-c579-4cf4-8d2e-aa8ad689b227
      version: -1
      name: IP prevalence check
      description: Get the prevalence of an IP, identified by ip_address.
      script: '|||core-get-IP-analytics-prevalence'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "78"
    scriptarguments:
      ip_address:
        complex:
          root: alert
          accessor: hostip
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "47":
    id: "47"
    taskid: a989b07f-5498-4e55-8f33-ee8d91c274a8
    type: title
    task:
      id: a989b07f-5498-4e55-8f33-ee8d91c274a8
      version: -1
      name: 'Investigation '
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "52"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1070,
          "y": 960
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "51":
    id: "51"
    taskid: c5e9aade-b872-48d6-87bd-2ed35118cd31
    type: playbook
    task:
      id: c5e9aade-b872-48d6-87bd-2ed35118cd31
      version: -1
      name: Handle False Positive Alerts
      description: |
        This playbook handles false positive alerts.
        It creates an alert exclusion or alert exception, or adds a file to an allow list based on the alert fields and playbook inputs.
      playbookName: Handle False Positive Alerts
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "30"
    scriptarguments:
      FileSHA256:
        complex:
          root: alert
          accessor: initiatorsha256
      ShouldCloseAutomatically:
        simple: "False"
      alertName:
        complex:
          root: alert
          accessor: name
      sourceIP:
        complex:
          root: alert
          accessor: hostip
      username:
        complex:
          root: alert
          accessor: username
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1610,
          "y": 1900
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "52":
    id: "52"
    taskid: 063d3d5e-5b5d-478e-8941-ffd93ed418d3
    type: title
    task:
      id: 063d3d5e-5b5d-478e-8941-ffd93ed418d3
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "81"
      - "82"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1070,
          "y": 1100
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "57":
    id: "57"
    taskid: 5ebfddc7-a504-4482-82a7-d0dc69f80a03
    type: title
    task:
      id: 5ebfddc7-a504-4482-82a7-d0dc69f80a03
      version: -1
      name: No Malicious activity identified
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "37"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1260,
          "y": 1590
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "59":
    id: "59"
    taskid: c5d2b9f8-b039-41e6-8c04-08c23a7abe46
    type: regular
    task:
      id: c5d2b9f8-b039-41e6-8c04-08c23a7abe46
      version: -1
      name: Check IP Reputation
      description: Checks the specified IP address against the AbuseIP database.
      script: '|||ip'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "78"
    scriptarguments:
      ip:
        complex:
          root: alert
          accessor: hostip
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1080,
          "y": 460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "61":
    id: "61"
    taskid: b2e0de5a-b3dc-4c56-8dd3-1d07e3166289
    type: condition
    task:
      id: b2e0de5a-b3dc-4c56-8dd3-1d07e3166289
      version: -1
      name: Found any persistence evidences or user abnormal activity?
      description: Checks if results are returned from the Cloud Threat Hunting - Persistence and Cloud User Investigation - Generic sub-playbooks.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "57"
      "yes":
      - "64"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: AWSQuery
            iscontext: true
          right:
            value: {}
        - operator: isNotEmpty
          left:
            value:
              simple: GCPQuery
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: AwsMFAConfigCount
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: AwsUserRoleChangesCount
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: AwsSuspiciousActivitiesCount
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: AwsScriptBasedUserAgentCount
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: GcpSuspiciousApiUsage
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: GsuiteUnusualLoginAllowedCount
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: GsuiteUserPasswordLeaked
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: AzureScriptBasedUserAgentEvents
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1070,
          "y": 1410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "64":
    id: "64"
    taskid: cf29d1b9-edb3-4f54-8b84-1864f001e721
    type: title
    task:
      id: cf29d1b9-edb3-4f54-8b84-1864f001e721
      version: -1
      name: Malicious Activity identified
      description: Optionally increases the alert severity to the new value if it is greater than the existing severity.
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "76"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 1590
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "73":
    id: "73"
    taskid: e5c52d38-39a3-40e1-83c8-6a43efbf30ef
    type: regular
    task:
      id: e5c52d38-39a3-40e1-83c8-6a43efbf30ef
      version: -1
      name: Get cloud extra data
      description: Returns information about each alert ID.
      script: '|||core-get-cloud-original-alerts'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      alert_ids:
        complex:
          root: alert
          accessor: id
      filter_alert_fields:
        simple: "false"
      ignore-outputs:
        simple: "false"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 20
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "76":
    id: "76"
    taskid: 3dd56123-770c-4681-841b-86dd7f338994
    type: title
    task:
      id: 3dd56123-770c-4681-841b-86dd7f338994
      version: -1
      name: Containment Plan
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "79"
      - "83"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 1900
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "78":
    id: "78"
    taskid: 4e2adb26-6b33-43af-8278-818c497109f7
    type: title
    task:
      id: 4e2adb26-6b33-43af-8278-818c497109f7
      version: -1
      name: Set Alert Verdict
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "32"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "79":
    id: "79"
    taskid: a5f34eb1-6d18-4061-8f2e-e71458a6e109
    type: playbook
    task:
      id: a5f34eb1-6d18-4061-8f2e-e71458a6e109
      version: -1
      name: Cloud Response - Generic
      description: |-
        This playbook provides response playbooks for:
        - AWS
        - Azure
        - GCP

        The response actions available are:
        - Terminate/Shut down/Power off an instance
        - Delete/Disable a user
        - Delete/Revoke/Disable credentials
        - Block indicators
      playbookName: Cloud Response - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "31"
    scriptarguments:
      AWS-userRemediationType:
        simple: Revoke
      Azure-userRemediationType:
        simple: Disable
      GCP-accessKeyRemediationType:
        simple: Disable
      GCP-userRemediationType:
        simple: Disable
      autoAccessKeyRemediation:
        simple: "False"
      autoBlockIndicators:
        complex:
          root: inputs.autoBlockIndicators
      autoResourceRemediation:
        simple: "False"
      autoUserRemediation:
        simple: ${inputs.autoUserRemediation}
      cloudProvider:
        complex:
          root: alert
          accessor: cloudprovider
      username:
        complex:
          root: alert.username
          filters:
          - - operator: notStartWith
              left:
                value:
                  simple: alert.username
                iscontext: true
              right:
                value:
                  simple: key1(
              ignorecase: true
            - operator: notStartWith
              left:
                value:
                  simple: alert.username
                iscontext: true
              right:
                value:
                  simple: key2(
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 930,
          "y": 2040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "81":
    id: "81"
    taskid: f860728f-cbbe-4cad-8d99-e22e8b8043a8
    type: playbook
    task:
      id: f860728f-cbbe-4cad-8d99-e22e8b8043a8
      version: -1
      name: Cloud Threat Hunting - Persistence
      description: |-
        ---

        ## Cloud Threat Hunting - Persistence Playbook

        The playbook is responsible for hunting persistence activity in the cloud. It supports AWS, GCP, and Azure - one at a time.

        ### Hunting Queries

        The playbook executes hunting queries for each provider related to each of the following:

        1. IAM
        2. Compute Resources
        3. Compute Functions

        ### Indicator Extraction

        If relevant events are found during the search, indicators will be extracted using the `ExtractIndicators-CloudLogging` script.

        ---
      playbookName: Cloud Threat Hunting - Persistence
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "61"
    scriptarguments:
      AWSAccessKeyID:
        complex:
          root: Core.OriginalAlert.event
          accessor: identity_invoked_by_uuid
      AWSTimespan:
        complex:
          root: alert
          accessor: timestamp
          transformers:
          - operator: ModifyDateTime
            args:
              variation:
                value:
                  simple: 2 hours ago
          - operator: Cut
            args:
              delimiter:
                value:
                  simple: +
              fields:
                value:
                  simple: "1"
      AzureTimespan:
        simple: 2h
      GCPProjectName:
        complex:
          root: alert
          accessor: cloudproject
      GCPTimespan:
        complex:
          root: alert
          accessor: timestamp
          transformers:
          - operator: ModifyDateTime
            args:
              variation:
                value:
                  simple: 2 hours ago
          - operator: replace
            args:
              limit: {}
              replaceWith:
                value:
                  simple: Z
              toReplace:
                value:
                  simple: "+00:00"
      cloudProvider:
        complex:
          root: alert
          accessor: cloudprovider
      region:
        complex:
          root: alert
          accessor: region
      username:
        complex:
          root: alert
          accessor: username
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1070,
          "y": 1240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "82":
    id: "82"
    taskid: 4b344065-3e29-433f-81ac-a7f34eac4b3a
    type: playbook
    task:
      id: 4b344065-3e29-433f-81ac-a7f34eac4b3a
      version: -1
      name: Cloud User Investigation - Generic
      description: |
        This playbook performs an investigation on a specific user in cloud environments, using queries and logs from Azure Log Analytics, AWS CloudTrail, G Suite Auditor, and GCP Logging.
      playbookName: Cloud User Investigation - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "61"
    scriptarguments:
      AwsTimeSearchFrom:
        simple: "1"
      AzureSearchTime:
        simple: ago(1d)
      GcpProjectName:
        complex:
          root: alert.cloudproject
          accessor: cloudproject
      GcpTimeSearchFrom:
        simple: "1"
      MfaAttemptThreshold:
        simple: "10"
      Username:
        complex:
          root: alert.username
          filters:
          - - operator: notStartWith
              left:
                value:
                  simple: alert.username
                iscontext: true
              right:
                value:
                  simple: key1(
              ignorecase: true
            - operator: notStartWith
              left:
                value:
                  simple: alert.username
                iscontext: true
              right:
                value:
                  simple: key2(
      cloudProvider:
        complex:
          root: alert
          accessor: cloudprovider
      failedLogonThreshold:
        simple: "20"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1550,
          "y": 1240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "83":
    id: "83"
    taskid: af782aef-ba76-45b9-87a3-e6e385bebb1e
    type: condition
    task:
      id: af782aef-ba76-45b9-87a3-e6e385bebb1e
      version: -1
      name: Should rotate the credentials automatically?
      description: Whether to rotate the credentials automatically.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "31"
      "yes":
      - "84"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.autoUserRemediation
            iscontext: true
          right:
            value:
              simple: "true"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 430,
          "y": 2040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "84":
    id: "84"
    taskid: ff0f8a46-1a28-46b7-81bf-512130aefb3a
    type: playbook
    task:
      id: ff0f8a46-1a28-46b7-81bf-512130aefb3a
      version: -1
      name: Cloud Credentials Rotation - Generic
      description: |-
        ## **Cloud Credentials Rotation - Generic**

        This comprehensive playbook combines the remediation steps from AWS, Azure, and GCP sub-playbooks into a single, cohesive guide. Regardless of which Cloud Service Provider (CSP) you're working with, this playbook will direct you to the relevant steps, ensuring swift and effective response.

        The primary objective is to offer an efficient way to address compromised credentials across different cloud platforms. By consolidating the key steps from AWS, Azure, and GCP, it minimizes the time spent searching for platform-specific procedures and accelerates the remediation process, ensuring the highest level of security for your cloud environments.

        ## **Integrations for Each Sub-Playbook**

        In order to seamlessly execute the actions mentioned in each sub-playbook, specific integrations are essential. These integrations facilitate the automated tasks and processes that the playbook carries out. Here are the required integrations for each sub-playbook:

        ### **AWS Sub-Playbook:**
        1. [**AWS - IAM**](https://xsoar.pan.dev/docs/reference/integrations/aws---iam): Used to manage AWS Identity and Access Management.
        2. [**AWS - EC2**](https://xsoar.pan.dev/docs/reference/integrations/aws---ec2): Essential for managing Amazon Elastic Compute Cloud (EC2) instances.

        ### **GCP Sub-Playbook:**
        1. [**Google Workspace Admin**](https://xsoar.pan.dev/docs/reference/integrations/g-suite-admin): Manages users, groups, and other entities within Google Workspace.
        2. [**GCP-IAM**](https://xsoar.pan.dev/docs/reference/integrations/gcp-iam): Ensures management and control of GCP's Identity and Access Management.

        ### **Azure Sub-Playbook:**
        1. [**Microsoft Graph Users**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-user): Manages users and related entities in Microsoft Graph.
        2. [**Microsoft Graph Applications**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-applications): Manages applications within Microsoft Graph.
      playbookName: Cloud Credentials Rotation - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "31"
    scriptarguments:
      AWS-accessKeyID:
        simple: ${Core.OriginalAlert.event.identity_orig.accessKeyId}
      AWS-instanceID:
        complex:
          root: alert.username
          filters:
          - - operator: containsGeneral
              left:
                value:
                  simple: alert.username
                iscontext: true
              right:
                value:
                  simple: i-
          transformers:
          - operator: Cut
            args:
              delimiter:
                value:
                  simple: /
              fields:
                value:
                  simple: "2"
      AWS-newInstanceProfileName:
        simple: ${inputs.AWS-newInstanceProfileName}
      AWS-newRoleName:
        simple: ${inputs.AWS-newRoleName}
      AWS-roleNameToRestrict:
        simple: ${inputs.AWS-roleNameToRestrict}
      AWS-userID:
        simple: ${alert.username}
      Azure-AppID:
        simple: ${Core.OriginalAlert.event.identity_orig.claims.appid}
      Azure-ObjectID:
        complex:
          root: Core.OriginalAlert.event.identity_orig
          accessor: claims
          transformers:
          - operator: Stringify
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: http://schemas.microsoft.com/identity/claims/objectidentifier":"\w{8}\-\w{4}\-\w{4}\-\w{4}\-\w{12}
              unpack_matches: {}
          - operator: ExtractInbetween
            args:
              from:
                value:
                  simple: http://schemas.microsoft.com/identity/claims/objectidentifier":"
              to:
                value:
                  simple: '"'
      Azure-userID:
        simple: ${alert.username}
      GCP-SAEmail:
        simple: ${Core.OriginalAlert.event.identity_orig.principalEmail}
      GCP-cloudProject:
        simple: ${alert.cloudproject}
      GCP-userID:
        simple: ${alert.username}
      GCP-zone:
        simple: ${Core.OriginalAlert.event.zone}
      RemediationType:
        simple: ${inputs.credentialsRemediationType}
      cloudProvider:
        simple: ${alert.cloudprovider}
      identityType:
        simple: ${alert.cloudidentitytype}
      shouldCloneSA:
        simple: ${inputs.shouldCloneSA}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 430,
          "y": 2230
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "32_47_#default#": 0.28,
      "32_64_Malicious": 0.21,
      "37_30_Finish Playbook": 0.15,
      "61_57_#default#": 0.61,
      "61_64_yes": 0.35,
      "83_31_#default#": 0.38,
      "83_84_yes": 0.44
    },
    "paper": {
      "dimensions": {
        "height": 2755,
        "width": 1710,
        "x": 280,
        "y": -120
      }
    }
  }
inputs:
- key: autoUserRemediation
  value:
    simple: "False"
  required: false
  description: 'Whether to execute the user remediation automatically. (Default: False)'
  playbookInputQuery:
- key: autoBlockIndicators
  value:
    simple: "False"
  required: false
  description: 'Whether to execute the block remediation automatically. (Default: False)'
  playbookInputQuery:
- key: credentialsRemediationType
  value:
    simple: Reset
  required: false
  description: |-
    The response playbook provides the following remediation actions using AWS, MSGraph Users, GCP and GSuite Admin:

    Reset: By entering "Reset" in the input, the playbook will execute password reset.
    Supports: AWS, MSGraph Users, GCP and GSuite Admin.

    Revoke: By entering "Revoke" in the input, the GCP will revoke the access key, GSuite Admin will revoke the access token and the MSGraph Users will revoke the session.
    Supports: GCP, GSuite Admin and MSGraph Users.

    Deactivate - By entering "Deactivate" in the input, the playbook will execute access key deactivation.
    Supports: AWS.

    ALL: By entering "ALL" in the input, the playbook will execute the all remediation actions provided for each CSP.
  playbookInputQuery:
- key: shouldCloneSA
  value:
    simple: "False"
  required: false
  description: |-
    Whether to clone the compromised SA before putting a deny policy to it.
    Supports: AWS.
    True/False
  playbookInputQuery:
- key: AWS-newInstanceProfileName
  value: {}
  required: false
  description: The new instance profile name to assign in the clone service account flow.
  playbookInputQuery:
- key: AWS-newRoleName
  value: {}
  required: false
  description: The new role name to assign in the clone service account flow.
  playbookInputQuery:
- key: AWS-roleNameToRestrict
  value: {}
  required: false
  description: If provided, the role will be attached with a deny policy without the compute instance analysis flow.
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
marketplaces: 
- marketplacev2
- platform
fromversion: 6.8.0
supportedModules:
- xsiam