Skip to content

Commit

Permalink
Merge branch 'develop' into THREAT-379/review-cr-schedule-and-lookbac…
Browse files Browse the repository at this point in the history
…k-intervals
  • Loading branch information
arielkr256 authored Nov 4, 2024
2 parents 907a7a7 + 9c745a6 commit a01690b
Show file tree
Hide file tree
Showing 4 changed files with 165 additions and 2 deletions.
4 changes: 2 additions & 2 deletions .github/workflows/check-packs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ jobs:
panther_analysis_tool check-packs || echo "errors=`cat errors.txt`" >> $GITHUB_OUTPUT
- name: Comment PR
uses: thollander/actions-comment-pull-request@e2c37e53a7d2227b61585343765f73a9ca57eda9
uses: thollander/actions-comment-pull-request@24bffb9b452ba05a4f3f77933840a6a841d1b32b
if: ${{ steps.check-packs.outputs.errors }}
with:
mode: upsert
Expand All @@ -57,7 +57,7 @@ jobs:
```
comment-tag: check-packs
- name: Delete comment
uses: thollander/actions-comment-pull-request@e2c37e53a7d2227b61585343765f73a9ca57eda9
uses: thollander/actions-comment-pull-request@24bffb9b452ba05a4f3f77933840a6a841d1b32b
if: ${{ !steps.check-packs.outputs.errors }}
with:
mode: delete
Expand Down
1 change: 1 addition & 0 deletions packs/aws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,7 @@ PackDefinition:
- AWS.CMK.KeyRotation
- AWS.DynamoDB.TableTTLEnabled
- AWS.EC2.Vulnerable.XZ.Image.Launched
- Amazon.EKS.AnonymousAPIAccess
- AWS.IAM.Policy.DoesNotGrantAdminAccess
- AWS.IAM.Policy.DoesNotGrantNetworkAdminAccess
- AWS.IAM.Resource.DoesNotHaveInlinePolicy
Expand Down
30 changes: 30 additions & 0 deletions rules/aws_eks_rules/anonymous_api_access.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
from panther_aws_helpers import eks_panther_obj_ref


def rule(event):
# Check if the username is set to "system:anonymous", which indicates anonymous access
p_eks = eks_panther_obj_ref(event)
if p_eks.get("actor") == "system:anonymous":
return True
return False


def title(event):
p_eks = eks_panther_obj_ref(event)
return (
f"Anonymous API access detected on Kubernetes API server "
f"from [{p_eks.get('sourceIPs')[0]}] to [{p_eks.get('resource')}] "
f"in namespace [{p_eks.get('ns')}] on [{p_eks.get('p_source_label')}]"
)


def dedup(event):
p_eks = eks_panther_obj_ref(event)
return f"anonymous_access_{p_eks.get('p_source_label')}_{p_eks.get('sourceIPs')[0]}"


def alert_context(event):
p_eks = eks_panther_obj_ref(event)
mutable_event = event.to_dict()
mutable_event["p_eks"] = p_eks
return dict(mutable_event)
132 changes: 132 additions & 0 deletions rules/aws_eks_rules/anonymous_api_access.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
AnalysisType: rule
Filename: anonymous_api_access.py
RuleID: "Amazon.EKS.AnonymousAPIAccess"
DisplayName: "EKS Anonymous API Access Detected"
Enabled: true
LogTypes:
- Amazon.EKS.Audit
Severity: Medium
Reports:
MITRE ATT&CK:
- "TA0001:T1190" # Initial Access: Exploit Public-Facing Application
Description: >
This rule detects anonymous API requests made to the Kubernetes API server.
In production environments, anonymous access should be disabled to prevent
unauthorized access to the API server.
DedupPeriodMinutes: 60
Reference:
https://kubernetes.io/docs/reference/access-authn-authz/authentication/#anonymous-requests
Runbook: >
Check the EKS cluster configuration and ensure that anonymous access
to the Kubernetes API server is disabled. This can be done by verifying the API
server arguments and authentication webhook configuration.
SummaryAttributes:
- user:username
- p_any_ip_addresses
- p_source_label
Tags:
- EKS
- Security Control
- API
- Initial Access:Exploit Public-Facing Application
Tests:
- Name: Anonymous API Access
ExpectedResult: true
Log:
{
"annotations": {
"authorization.k8s.io/decision": "allow",
"authorization.k8s.io/reason": "RBAC: allowed by ClusterRoleBinding system:public-info-viewer"
},
"apiVersion": "audit.k8s.io/v1",
"auditID": "abcde12345",
"kind": "Event",
"level": "Request",
"objectRef": {
"apiVersion": "v1",
"name": "test-pod",
"namespace": "default",
"resource": "pods"
},
"p_any_aws_account_ids": [
"123412341234"
],
"p_any_aws_arns": [
"arn:aws:iam::123412341234:role/DevAdministrator"
],
"p_any_ip_addresses": [
"8.8.8.8"
],
"p_any_usernames": [
"system:anonymous"
],
"p_event_time": "2022-11-29 00:09:04.38",
"p_log_type": "Amazon.EKS.Audit",
"p_parse_time": "2022-11-29 00:10:25.067",
"p_row_id": "2e4ab474b0f0f7a4a8fff4f014a9b32a",
"p_source_id": "4c859cd4-9406-469b-9e0e-c2dc1bee24fa",
"p_source_label": "example-cluster-eks-logs",
"requestReceivedTimestamp": "2022-11-29 00:09:04.38",
"requestURI": "/api/v1/namespaces/default/pods/test-pod",
"responseStatus": {
"code": 200
},
"sourceIPs": [
"8.8.8.8"
],
"stage": "ResponseComplete",
"user": {
"username": "system:anonymous"
},
"userAgent": "kubectl/v1.25.4"
}
- Name: Non-Anonymous API Access
ExpectedResult: false
Log:
{
"annotations": {
"authorization.k8s.io/decision": "allow",
"authorization.k8s.io/reason": "RBAC: allowed by ClusterRoleBinding system:public-info-viewer"
},
"apiVersion": "audit.k8s.io/v1",
"auditID": "abcde12345",
"kind": "Event",
"level": "Request",
"objectRef": {
"apiVersion": "v1",
"name": "test-pod",
"namespace": "default",
"resource": "pods"
},
"p_any_aws_account_ids": [
"123412341234"
],
"p_any_aws_arns": [
"arn:aws:iam::123412341234:role/DevAdministrator"
],
"p_any_ip_addresses": [
"8.8.8.8"
],
"p_any_usernames": [
"kubernetes-admin"
],
"p_event_time": "2022-11-29 00:09:04.38",
"p_log_type": "Amazon.EKS.Audit",
"p_parse_time": "2022-11-29 00:10:25.067",
"p_row_id": "2e4ab474b0f0f7a4a8fff4f014a9b32a",
"p_source_id": "4c859cd4-9406-469b-9e0e-c2dc1bee24fa",
"p_source_label": "example-cluster-eks-logs",
"requestReceivedTimestamp": "2022-11-29 00:09:04.38",
"requestURI": "/api/v1/namespaces/default/pods/test-pod",
"responseStatus": {
"code": 200
},
"sourceIPs": [
"8.8.8.8"
],
"stage": "ResponseComplete",
"user": {
"username": "kubernetes-admin"
},
"userAgent": "kubectl/v1.25.4"
}

0 comments on commit a01690b

Please sign in to comment.