diff --git a/MODULES/Cloud-01-AWS-IAM-Privilege-Escalation-via-AttachUserPolicy.py b/MODULES/Cloud-01-AWS-IAM-Privilege-Escalation-via-AttachUserPolicy.py index b1d8cf7..387f7ab 100644 --- a/MODULES/Cloud-01-AWS-IAM-Privilege-Escalation-via-AttachUserPolicy.py +++ b/MODULES/Cloud-01-AWS-IAM-Privilege-Escalation-via-AttachUserPolicy.py @@ -107,12 +107,12 @@ class Module(BaseModule): artifacts.append(ArtifactModel(type=ArtifactType.ACCOUNT, role=ArtifactRole.RELATED, value=account_id, name="AWS Account ID")) # 3. 计算 correlation_uid (Correlation Logic) - # 选择 [主体用户, 目标用户, 账号] 作为聚合键,这能有效捕获针对特定目标的持续攻击 + # 选择 [目标用户, 账号] 作为聚合键,这能有效捕获针对特定目标的持续攻击 correlation_uid = Correlation.generate_correlation_uid( rule_id=self.module_name, time_window="24h", - keys=[principal_user, target_user, account_id], + keys=[target_user, account_id], timestamp=event_time_formatted ) @@ -194,7 +194,7 @@ class Module(BaseModule): else: # 根据 Alert 计算 Case字段 new_case = CaseModel( - title=f"Potential IAM Privilege Escalation in Account {account_id}", + title=f"Potential IAM Privilege Escalation in Account {account_id} by {target_user}", severity=severity, impact=Impact.HIGH if outcome == "success" else Impact.MEDIUM, priority=CasePriority.HIGH if outcome == "success" else CasePriority.MEDIUM, @@ -225,7 +225,7 @@ if __name__ == "__main__": # 批量测试最早的100条告警 module = Module() - message_ids = module.read_stream_head_ids(3) + message_ids = module.read_stream_head_ids(100) for message_id in message_ids: module.debug_message_id = message_id module.run() diff --git a/PLUGINS/Mock/SIEM/scenarios/cloud.py b/PLUGINS/Mock/SIEM/scenarios/cloud.py index 3a6f5e9..b674257 100644 --- a/PLUGINS/Mock/SIEM/scenarios/cloud.py +++ b/PLUGINS/Mock/SIEM/scenarios/cloud.py @@ -10,7 +10,7 @@ class CloudPrivilegeEscalationScenario(object): self.attacker_user = random.choice(settings.IAM_USERS) self.target_account = random.choice(settings.AWS_ACCOUNTS) self.region = random.choice(settings.REGIONS) - self.malicious_new_user = f"service_account_{random.randint(1000, 1020)}" + self.malicious_new_user = f"service_account_{random.randint(1000, 1002)}" self.attacker_key = f"AKIA{uuid.uuid4().hex[:16].upper()}" self.malicious_key = f"AKIA{uuid.uuid4().hex[:16].upper()}" self.malicious_user_id = f"AIDAI{uuid.uuid4().hex[:16].upper()}" diff --git a/PLUGINS/Mock/SIEM/settings.py b/PLUGINS/Mock/SIEM/settings.py index 743c02f..fcda33a 100644 --- a/PLUGINS/Mock/SIEM/settings.py +++ b/PLUGINS/Mock/SIEM/settings.py @@ -49,13 +49,9 @@ PROCESSES = [ # 云环境实体池 # --- 云环境实体扩展 --- -AWS_ACCOUNTS = [f"12345678{i:04d}" for i in range(1, 5)] +AWS_ACCOUNTS = [f"12345678{i:04d}" for i in range(1, 3)] -IAM_USERS = [ - "admin-cli", "terraform-executor", "github-actions-role", - "read-only-auditor", "break-glass-admin", - "dev-user-alpha", "dev-user-beta", "billing-manager" - ] + [f"iam-user-{i:02d}" for i in range(1, 5)] +IAM_USERS = ["admin-cli", "terraform-executor", "github-actions-role", "iam-user-01"] REGIONS = [ "us-east-1", "us-west-2", "eu-central-1", "eu-west-1",