Name:AWS Unusual Number of Failed Authentications From Ip id:0b5c9c2b-e2cb-4831-b4f1-af125ceb1386 version:15 date:None author:Bhavin Patel, Splunk status:production type:Anomaly Description:The following analytic identifies a single source IP failing to authenticate into the AWS Console with multiple valid users. It uses CloudTrail logs and calculates the standard deviation for source IP, leveraging the 3-sigma rule to detect unusual numbers of failed authentication attempts. This behavior is significant as it may indicate a Password Spraying attack, where an adversary attempts to gain initial access or elevate privileges. If confirmed malicious, this activity could lead to unauthorized access, data breaches, or further exploitation within the AWS environment. Data_source:
| rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region
| bucket span=10m _time
| stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts values(action) as action values(dest) as dest values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent BY _time, src
| eventstats avg(distinct_attempts) as avg_attempts , stdev(distinct_attempts) as ip_std BY _time
how_to_implement:You must install Splunk Add-on for AWS in order to ingest Cloudtrail. We recommend the users to try different combinations of the bucket span time and the calculation of the upperBound field to tune this search according to their environment known_false_positives:No known false postives for this detection. Please review this alert References: -https://attack.mitre.org/techniques/T1110/003/ -https://www.whiteoaksecurity.com/blog/goawsconsolespray-password-spraying-tool/ -https://softwaresecuritydotblog.wordpress.com/2019/09/28/how-to-protect-against-credential-stuffing-on-aws/ drilldown_searches: name:'View the detection results for - "$tried_accounts$"' search:'%original_detection_search% | search tried_accounts = "$tried_accounts$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$tried_accounts$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$tried_accounts$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['AWS Identity and Access Management Account Takeover']