| ID | Technique | Tactic |
|---|---|---|
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
Detection: Prohibited Network Traffic Allowed
Description
The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the "lookup_interesting_ports" table, is allowed. It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies. This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration. If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization's security posture.
Search
1
2| tstats `security_content_summariesonly`
3 count min(_time) as firstTime
4 max(_time) as lastTime
5 values(All_Traffic.src_port) as src_port
6 values(All_Traffic.action) as action
7 values(All_Traffic.rule) as rule
8
9FROM datamodel=Network_Traffic WHERE
10
11All_Traffic.action IN ("allowed", "allow")
12[
13
14| inputlookup interesting_ports_lookup where is_prohibited="true"
15
16| table dest_port transport
17
18| dedup dest_port transport
19
20| rename dest_port as All_Traffic.dest_port
21
22| rename transport as All_Traffic.transport
23]
24
25by All_Traffic.src_ip All_Traffic.dest_ip
26 All_Traffic.dest_port All_Traffic.dvc
27 All_Traffic.transport All_Traffic.vendor_product
28
29
30| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note
31
32
33| `security_content_ctime(firstTime)`
34
35| `security_content_ctime(lastTime)`
36
37| `drop_dm_object_name("All_Traffic")`
38
39| `prohibited_network_traffic_allowed_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Cisco Secure Firewall Threat Defense Connection Event | Other | 'cisco:sfw:estreamer' |
'not_applicable' |
Macros Used
| Name | Value |
|---|---|
| security_content_ctime | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$) |
| prohibited_network_traffic_allowed_filter | search * |
prohibited_network_traffic_allowed_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search also requires the Network_Traffic data model be populated.
Known False Positives
The "interesting_ports_lookup" lookup considers communication to ports like 20, 21 for FTP, 23 for Telnet, 110 for POP3, etc. as prohibited traffic. Which may result in a lot of alerts in certain environments that still rely on these ports for legitimate traffic. Tune as needed.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| Potentially Prohibited Network Traffic on Port [$dest_port$] via Protocol [$transport$] allowed from [$src_ip$]. | src_ip | system | 20 |
Threat Objects
| Field | Type |
|---|---|
| dest_ip | ip_address |
References
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | not_applicable |
cisco:sfw:estreamer |
| Integration | ✅ Passing | Dataset | not_applicable |
cisco:sfw:estreamer |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 15