Skip to content
This repository was archived by the owner on Sep 16, 2026. It is now read-only.

Commit e771c3d

Browse files
authored
feat: detection for AWS Macie Evasion (panther-labs#520)
Co-authored-by: Jack Naglieri <jack@panther.io>
1 parent df70f0a commit e771c3d

4 files changed

Lines changed: 250 additions & 3 deletions

File tree

‎README.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,11 +87,12 @@ pipenv run panther_analysis_tool zip --filter Severity=Critical
8787
8888
### Upload detections to your Panther instance
8989
```bash
90+
# Note: Set your AWS access keys and region env variables before running the `upload` command
91+
92+
export AWS_REGION=us-east-1
9093
pipenv run panther_analysis_tool upload [-h] [--path PATH] [--out OUT]
9194
[--filter KEY=VALUE [KEY=VALUE ...]]
9295
[--debug]
93-
94-
# Important: Make sure you have access keys and region settings set for the AWS account running Panther
9596
```
9697
9798
Global helper functions are defined in the `global_helpers` folder. This is a hard coded location and cannot change. However, you may create as many files as you'd like under this path. Simply import them into your detections by the specified `GlobalID`.
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
from panther_base_helpers import deep_get, pattern_match
2+
3+
MACIE_EVENTS = {
4+
"ArchiveFindings",
5+
"CreateFindingsFilter",
6+
"DeleteMember",
7+
"DisassociateFromMasterAccount",
8+
"DisassociateMember",
9+
"DisableMacie",
10+
"DisableOrganizationAdminAccount",
11+
"UpdateFindingsFilter",
12+
"UpdateMacieSession",
13+
"UpdateMemberSession",
14+
"UpdateClassificationJob",
15+
}
16+
17+
18+
def rule(event):
19+
return event.get("eventName") in MACIE_EVENTS and pattern_match(
20+
event.get("eventSource"), "macie*.amazonaws.com"
21+
)
22+
23+
24+
def title(event):
25+
account = event.get("recipientAccountId")
26+
user_arn = deep_get(event, "userIdentity", "arn")
27+
return f"AWS Macie in AWS Account [{account}] Disabled/Updated by [{user_arn}]"
Lines changed: 219 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,219 @@
1+
AnalysisType: rule
2+
Filename: aws_macie_evasion.py
3+
RuleID: AWS.Macie.Evasion
4+
DisplayName: AWS Macie Disabled/Updated
5+
Enabled: true
6+
LogTypes:
7+
- AWS.CloudTrail
8+
Reports:
9+
MITRE ATT&CK:
10+
- 'TA0005:T1562' # Tactic ID:Technique ID (https://attack.mitre.org/tactics/enterprise/)
11+
Severity: Medium
12+
Description: >
13+
Amazon Macie is a data security and data privacy service to discover and protect sensitive data.
14+
Security teams use Macie to detect open S3 Buckets that could have potentially sensitive data in it along with
15+
policy violations, such as missing Encryption. If an attacker disables Macie, it could potentially hide data exfiltration.
16+
Reference: https://aws.amazon.com/macie/
17+
Runbook: >
18+
Analyze the events to ensure it's not normal maintenance.
19+
If it's abnormal, run the Indicator Search on the UserIdentity:Arn for the past hour and analyze other services accessed/changed.
20+
DedupPeriodMinutes: 60
21+
Threshold: 5
22+
SummaryAttributes:
23+
- awsRegion
24+
- eventName
25+
- p_any_aws_arns
26+
- p_any_ip_addresses
27+
- userIdentity:type
28+
- userIdentity:arn
29+
Tests:
30+
-
31+
Name: ListMembers
32+
ExpectedResult: false
33+
Log:
34+
{
35+
"awsRegion": "us-west-1",
36+
"eventCategory": "Management",
37+
"eventID": "5b3e4cf6-c37d-4c8c-9016-b8444a37ceaa",
38+
"eventName": "ListMembers",
39+
"eventSource": "macie2.amazonaws.com",
40+
"eventTime": "2022-09-27 18:11:33",
41+
"eventType": "AwsApiCall",
42+
"eventVersion": "1.08",
43+
"managementEvent": true,
44+
"p_any_aws_account_ids": [
45+
"123456789012"
46+
],
47+
"p_any_aws_arns": [
48+
"arn:aws:iam::123456789012:role/Admin",
49+
"arn:aws:sts::123456789012:assumed-role/Admin/Jack"
50+
],
51+
"p_any_ip_addresses": [
52+
"178.253.78.209"
53+
],
54+
"p_any_trace_ids": [
55+
"AAAASSSST64ZTHFY7777"
56+
],
57+
"p_event_time": "2022-09-27 18:11:33",
58+
"p_log_type": "AWS.CloudTrail",
59+
"p_parse_time": "2022-09-27 18:16:43.428",
60+
"p_row_id": "665d45a409cad7d68ff7bbd4138d02",
61+
"p_source_id": "b00eb354-da7a-49dd-9cc6-32535e32096a",
62+
"p_source_label": "CloudTrail Test",
63+
"readOnly": true,
64+
"recipientAccountId": "123456789012",
65+
"requestID": "2164bbea-3eb0-444b-8e10-8ba53b3460b6",
66+
"requestParameters": {
67+
"maxResults": "1",
68+
"onlyAssociated": "true"
69+
},
70+
"sourceIPAddress": "178.253.78.209",
71+
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36",
72+
"userIdentity": {
73+
"accessKeyId": "AAAASSSST64ZTHFY7777",
74+
"accountId": "123456789012",
75+
"arn": "arn:aws:sts::123456789012:assumed-role/Admin/Jack",
76+
"principalId": "AAAAA44444LE6DYFKKKKK:Jack",
77+
"sessionContext": {
78+
"attributes": {
79+
"creationDate": "2022-09-27T17:56:01Z",
80+
"mfaAuthenticated": "true"
81+
},
82+
"sessionIssuer": {
83+
"accountId": "123456789012",
84+
"arn": "arn:aws:iam::123456789012:role/Admin",
85+
"principalId": "AAAAA44444LE6DYFKKKKK",
86+
"type": "Role",
87+
"userName": "Admin"
88+
},
89+
"webIdFederationData": {}
90+
},
91+
"type": "AssumedRole"
92+
}
93+
}
94+
-
95+
Name: UpdateSession # The title of the test
96+
ExpectedResult: true # If the sample event should generate an alert or not
97+
Log:
98+
{
99+
"awsRegion": "us-east-2",
100+
"eventCategory": "Management",
101+
"eventID": "63033dfd-08c9-42f3-80ae-dca45e86ae84",
102+
"eventName": "UpdateMacieSession",
103+
"eventSource": "macie2.amazonaws.com",
104+
"eventTime": "2022-09-27 19:59:08",
105+
"eventType": "AwsApiCall",
106+
"eventVersion": "1.08",
107+
"managementEvent": true,
108+
"p_any_aws_account_ids": [
109+
"123456789012"
110+
],
111+
"p_any_aws_arns": [
112+
"arn:aws:iam::123456789012:role/Admin",
113+
"arn:aws:sts::123456789012:assumed-role/Admin/Jack"
114+
],
115+
"p_any_ip_addresses": [
116+
"46.91.25.204"
117+
],
118+
"p_any_trace_ids": [
119+
"ASIASWJRT64Z42HFV6QX"
120+
],
121+
"p_event_time": "2022-09-27 19:59:08",
122+
"p_log_type": "AWS.CloudTrail",
123+
"p_parse_time": "2022-09-27 20:02:43.816",
124+
"p_row_id": "665d45a409cad7d68ff7bbd4138123",
125+
"p_source_id": "b00eb354-da7a-49dd-9cc6-32535e32096a",
126+
"p_source_label": "CloudTrail Test",
127+
"readOnly": false,
128+
"recipientAccountId": "123456789012",
129+
"requestID": "1b9981dc-21d2-4f77-92b0-69e23c8a40de",
130+
"requestParameters": {
131+
"findingPublishingFrequency": "SIX_HOURS"
132+
},
133+
"sourceIPAddress": "46.91.25.204",
134+
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36",
135+
"userIdentity": {
136+
"accessKeyId": "ASIASWJRT64Z42HFV6QX",
137+
"accountId": "123456789012",
138+
"arn": "arn:aws:sts::123456789012:assumed-role/Admin/Jack",
139+
"principalId": "AAAAA44444LE6DYFKKKKK:Jack",
140+
"sessionContext": {
141+
"attributes": {
142+
"creationDate": "2022-09-27T17:56:01Z",
143+
"mfaAuthenticated": "true"
144+
},
145+
"sessionIssuer": {
146+
"accountId": "123456789012",
147+
"arn": "arn:aws:iam::123456789012:role/Admin",
148+
"principalId": "AAAAA44444LE6DYFKKKKK",
149+
"type": "Role",
150+
"userName": "Admin"
151+
},
152+
"webIdFederationData": {}
153+
},
154+
"type": "AssumedRole"
155+
}
156+
}
157+
-
158+
Name: UpdateSession (Macie v1 event) # The title of the test
159+
ExpectedResult: true # If the sample event should generate an alert or not
160+
Log:
161+
{
162+
"awsRegion": "us-east-2",
163+
"eventCategory": "Management",
164+
"eventID": "63033dfd-08c9-42f3-80ae-dca45e86ae84",
165+
"eventName": "UpdateMacieSession",
166+
"eventSource": "macie.amazonaws.com",
167+
"eventTime": "2022-09-27 19:59:08",
168+
"eventType": "AwsApiCall",
169+
"eventVersion": "1.08",
170+
"managementEvent": true,
171+
"p_any_aws_account_ids": [
172+
"123456789012"
173+
],
174+
"p_any_aws_arns": [
175+
"arn:aws:iam::123456789012:role/Admin",
176+
"arn:aws:sts::123456789012:assumed-role/Admin/Jack"
177+
],
178+
"p_any_ip_addresses": [
179+
"46.91.25.204"
180+
],
181+
"p_any_trace_ids": [
182+
"ASIASWJRT64Z42HFV6QX"
183+
],
184+
"p_event_time": "2022-09-27 19:59:08",
185+
"p_log_type": "AWS.CloudTrail",
186+
"p_parse_time": "2022-09-27 20:02:43.816",
187+
"p_row_id": "665d45a409cad7d68ff7bbd4138123",
188+
"p_source_id": "b00eb354-da7a-49dd-9cc6-32535e32096a",
189+
"p_source_label": "CloudTrail Test",
190+
"readOnly": false,
191+
"recipientAccountId": "123456789012",
192+
"requestID": "1b9981dc-21d2-4f77-92b0-69e23c8a40de",
193+
"requestParameters": {
194+
"findingPublishingFrequency": "SIX_HOURS"
195+
},
196+
"sourceIPAddress": "46.91.25.204",
197+
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36",
198+
"userIdentity": {
199+
"accessKeyId": "ASIASWJRT64Z42HFV6QX",
200+
"accountId": "123456789012",
201+
"arn": "arn:aws:sts::123456789012:assumed-role/Admin/Jack",
202+
"principalId": "AAAAA44444LE6DYFKKKKK:Jack",
203+
"sessionContext": {
204+
"attributes": {
205+
"creationDate": "2022-09-27T17:56:01Z",
206+
"mfaAuthenticated": "true"
207+
},
208+
"sessionIssuer": {
209+
"accountId": "123456789012",
210+
"arn": "arn:aws:iam::123456789012:role/Admin",
211+
"principalId": "AAAAA44444LE6DYFKKKKK",
212+
"type": "Role",
213+
"userName": "Admin"
214+
},
215+
"webIdFederationData": {}
216+
},
217+
"type": "AssumedRole"
218+
}
219+
}

‎templates/example_rule.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ DisplayName: Human Readable Detection Name
55
Enabled: true
66
LogTypes:
77
- LogType.Name # https://docs.panther.com/data-onboarding/supported-logs
8-
Tags:
8+
Tags: # (Optional)
99
- Tag
1010
Reports: # (Optional)
1111
MITRE ATT&CK:

0 commit comments

Comments
 (0)