Threat Stack's Frequently Asked Questions page is a central hub where its customers can always go to with their most common questions. These are the 158 most popular questions Threat Stack receives.
Organization Owner
I set up Threat Stack and invited a user through my Identity Provider (IdP) and theycan'tget in?
An IdP invitation does not replace the need for a Threat Stack invitation. You have to provision users in IdP and send them an invitation through Threat Stack.
Why did I lose access to organizations, in which I am a user, after I converted the organization I own to SSO?
For security reasons, Threat Stack does not allow users to authenticate into multiple organizations that have different authentication protocols.
If you are a user of multiple organizations that have different authentication protocols, and you convert the organization you own to SSO, Threat Stack removes you from the other organizations.
Why was a user revoked from my organization after I converted it to SSO?
For security reasons, Threat Stack removes a user from the SSO converted organization if that user belongs to a Threat Stack Organization in which the authentication protocol differs from that of the organization being converted.
Everyone
Why can't I send a user an invite to my Threat Stack organization?
For security reasons, Threat Stack will not send an invitation to users that have been identified as outside of your IdP.
When I enter my email, I am automatically logged in, but not as the user with the email I entered into the sign-in. Why does this happen?
Identity Providers cookie very aggressively. If you, or someone else, has logged in as a different user, and that user also exists in Threat Stack, your IdP automatically tells Threat Stack to log you in as the user associated with your current IdP session.
To fix this and login as yourself, you can:
Open a new incognito window
Clear your cookies at the IdP and Threat Stack
Identity Providers typically support mappings from a user in the Identity Provider to an email address for a user in the Service Provider (Threat Stack). Using custom mappings, an email address in the IdP can be mapped to a user with a different email address in Threat Stack.
We recommend that users use the same email address in your IdP as in Threat Stack.
We enabled SSO for Threat Stack, why am I getting redirected to log in through the basic Threat Stack log in page?
As part of the authentication process, Threat Stack uses cookies and you may still be cookied to through the OAuth authentication path.
We recommend that you:
Open a new incognito window
Clear your cookies at the IdP and Threat Stack
Why am I stuck at the Threat Stack login page?
Use case: I entered my email, was redirected to my IdP, and I logged in successfully. I was redirected to Threat Stack and now I'm stuck at the login page.
You may not have received an invitation to Threat Stack for your SSO email address. Have your Organization Owner send you a Threat Stack invitation so you can create a new account associated with you SSO email address..
If no one in your organization can access Threat Stack, this suggests that the SSO was misconfigured for your Threat Stack Account and you should contact our support team.
Why am I stuck in an infinite loop between my IdP and Threat Stack?
This suggests that the Threat Stack IdP application was misconfigured, particularly the ACS Redirect Url. Contact your identity provider admin to check IdP configurations.
I have multiple organizations. How do I convert them all to SSO?
At this time, converting multiple organizations to SSO requires help from a Threat Stack support team member.
I was added to my IdP but Ican'tlogin?
Threat Stack compares users within our application to users authorized in the IdP. To access Threat Stack you must be listed in both places, or we block you from logging in.
If the email you use for Threat Stack does not match your email in your IdP, contact support.
I was added to Threat Stack but Ican'tlogin?
Threat Stack compares users within our application to users authorized in the IdP. To access Threat Stack you must be listed in both places, or we block you from logging in.
Why was I logged out of Threat Stack even though I was working on something?
Threat Stack enforces a hard eight hour session timeout for all Threat Stack user accounts, regardless of your activity level or authentication method.
View ArticleThe Threat Stack Cloud Security Platform (CSP) automatically assigns you with a REST API key. Your API key is a unique identifier that allows you to gain access to Threat Stack API resources.
Important
Each user within an organization is assigned a unique API key.
View Your API Key
Log into the Threat Stack CSP.
Click the Settings tab. The General Settings tab displays.
Click the Application Keys tab. In the REST API Key section, your API key displays.
Note
Your organization and user IDs also display in this section.
Reset Your API Key
Threat Stack recommends resetting your API key if it is exposed to someone outside of your organization, such as a Threat Stack support request in which you include your API key.
Log into the Threat Stack CSP.
Click the Settings tab. The General Settings tab displays.
Click the Application Keys tab. In the REST API Key section, your API key displays.
Click the Reset API Key button. The API key resets and changes to a new, unique identifier.
View ArticleThe Threat Stack Cloud Security Platform (CSP) normalizes the structure of raw events received before batching them for export.
Linux Agent
Agent 2.1
Threat Stack Agent 2.1 includes all of the raw event formats available in Agent 2.0, along with these additional formats.
Kubernetes Config Event Kubernetes Audit Link
Event Type
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
Subfield
Subfield Format
Subfield
Subfield Format
Kubernetes
event
array
id
string
tsEventType*
"kubernetesConfig"
ingestTime
long
agentId*
string
name
string
namespace
string
organizationId*
string
spec
array
role_bindings
optional object
targets
optional array
name
string
namespaces
string
type
string
roleName
string
roleType
string
role_policies
optional array
apiGroups
optional array
items
string
resourceNames
optional array
items
string
resources
optional array
items
string
verbs
array
items
string
timestamp*
long
type
"ClusterRole" "Role" "ClusterRoleBindings" "RoleBindings"
uid
string
*The field is searchable with Threat Stack Event Search.
Event Type
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
Kubernetes
event
array
id
string
tsEventType*
"kubernetesAudit"
ingestTime
long
action
string
agentId*
string
details
string
namespace
string
nodeName
string
nodeUid
string
organizationId*
string
resource
object
name
string
namespace
string
type
string
uid
string
timestamp*
long
* The field is searchable with Threat Stack Event Search
Agent 2.0
Audit File Host Login ThreatIntel
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"audit"
ingestTime
long
agentId
string
args
array
element
string
arguments
string
command*
string
connection*
struct
addr
string
dst_addr
string
dst_port
long
port
long
src_addr
string
src_port
long
version
long
containerId*
string
containerImage*
string
cwd*
string
egid
long
euid
long
exe
string
exit*
string
fd*
long
gid
long
group
string
loginuid
long
organizationId
string
path
array
element
string
pid
long
pod_name*
string
pod_uid*
string
ppid*
long
session
long
success*
boolean
syscall
string
timestamp
long
tty*
string
type
string
"accept" "bind" "connect" "listen" "start"
uid
long
user
string
* The value of "audit" > "type" determines whether or not this field displays.
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"file"
ingestTime
long
agentId
string
arguments
string
command
string
events
array
element
string
file_size
long
filename
string
gid
long
group
string
organizationId
string
pid
long
ppid
long
rule_id
string
rule_name
string
session
long
timestamp
long
total
long
uid
long
user
string
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"host"
ingestTime
long
agentId
string
comment
string
group
string
groups
array
element
string
hostname
string
level
long
location
string
log
string
organizationId
string
sigid
long
src_ip
string
timestamp
long
user
string
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"login"
ingestTime
long
agentId
string
exit
string
id
string
logout**
string
organizationId
string
pid
long
session
long
src_host
string
src_ip
string
timestamp
long
tty
string
type
string
"login" "logout"
uid
long
user
string
** If the value of "audit" > "type" is "logout," then this field displays.
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"threatintel"
ingestTime
long
agentId
string
command
string
connection
struct
addr
string
dst_addr
string
dst_port
long
port
long
src_addr
string
src_port
long
version
long
cwd
string
event_type
"threatintel"
exe
string
exit
string
fd
long
gid
long
group
string
ip
string
is_agent_2
boolean
organizationId
string
pid
long
ppid
long
ses
long
syscall
string
threatintel_event_id
string
threatintel_reason
string
threatintel_source
string
threatintel_type
"ip"
timestamp
long
tty
string
type
"accept"
uid
long
user
string
Agent 1.9
Audit File Host Login ThreatIntel
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"audit"
ingestTime
long
agentId
string
args
array
element
string
arguments
string
command*
string
connection*
struct
addr
string
dst_addr
string
dst_port
long
port
long
src_addr
string
src_port
long
version
long
containerId*
string
containerImage*
string
cwd*
string
egid
long
euid
long
exe*
string
exit*
string
fd*
long
gid
long
group
string
loginuid
long
organizationId
string
path
array
element
string
pid
long
pod_name*
string
pod_uid*
string
ppid*
long
session
long
success*
boolean
syscall
string
timestamp
long
tty*
string
type
string
"accept" "access" "adjtimex" "bind" "brk" "chdir" "chmod" "chown" "clock_gettime" "clock_settime" "close" "connect" "epoll_ctl" "fchmod" "fchown" "fcntl" "finit_module" "flock" "fstat" "ftruncate" "futex" "getdents" "getresgid" "geteuid" "getsockname" "getsockopt" "gettimeofday" "init_module" "inotify_add_watch" "ioctl" "ioprio_get" "listen" "lseek" "lstat" "mkdir" "mmap" "mount" "mprotect" "munmap" "newfstatat" "open" "openat" "pipe" "poll" "pselect6" "pwrite64" "read" "readlink" "readlinkat" "recvfrom" "recvmsg" "rename" "rmdir" "select" "sendmsg" "sendmmsg" "sendto" "setrlimit" "setsockopt" "settimeofday" "setxattr" "shutdown" "start" "stat" "umount2" "unlink" "unlinkat" "unshare" "utimes" "wait4" "write" "writev"
uid
long
user
string
* The value of audit > type determines whether or not this field displays.
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"file"
ingestTime
long
agentId
string
arguments
string
command
string
events
array
element
string
file_size
long
filename
string
gid
long
group
string
organizationId
string
pid
long
ppid
long
rule_id
string
rule_name
string
session
long
timestamp
long
total
long
uid
long
user
string
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"host"
ingestTime
long
agentId
string
auid**
long
caddr**
string
comment
string
function**
string
group
string
groups
array
element
string
header**
struct
id
long
milliseconds
long
pid
long
timestamp
long
hostname
string
level
long
library
string
location
string
log
string
organizationId
string
original_library**
string
overriding_library**
string
pid
long
raddr**
string
ses**
long
sigid
long
src_ip
string
subj**
string
timestamp
long
type
string
"LD_conflict" "null"
uid**
long
user
string
** If the value of audit > type is LD_conflict, then these fields displays.
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"login"
ingestTime
long
agentId
string
command***
string
exit_status***
struct
code
long
termination
long
id
string
logout***
string
new_session_pid
long
organizationId
string
parent_session***
long
pid
long
session
long
src_host***
string
src_ip***
string
timestamp
long
tty***
string
type
string
"login" "logout" "session_update"
uid
long
user
string
*** The value of login > type determines whether or not this field displays.
Field
Field Format
Subfield
Subfield Format
Subfield
Subfield Format
event
array
id
string
tsEventType
"threatintel"
ingestTime
long
agentId
string
args
array
element
string
arguments
string
command
string
connection
struct
addr
string
dst_addr
string
dst_port
long
port
long
src_addr****
string
src_port****
long
version
long
egid
long
euid
long
event_type
"threatintel"
exe
string
exit
string
fd****
long
gid
long
group
string
ip
string
organizationId
string
path
array
element
string
pid
long
ppid
long
session
long
syscall
string
threatintel_event_id
string
threatintel_reason
string
threatintel_source
string
threatintel_type
"ip"
timestamp
long
tty
string
type
string
"accept" "connect"
uid
long
user
string
****If the value of threatintel > type is accept, then this field displays.
Windows Agent
Agent 2.0.0w and beyond
Note
Windows events will contain a subset of fields shown in the table below.
Event Type
Field
Field Format
Subfield
Subfield Format
Windows
event
array
id
string
tsEventType*
"winsec"
type
"Audit Policy Change" "Computer Account Management" "Credential Validation" "Firewall" "Logon" "Logoff" "Process Creation" "Process Termination" "Security Group Management" "Security State Change" "Security System Extension" "System Integrity" "User Account Management"
access
string
allowed_delegates
string
audit_category
string
audit_guid
string
audit_guid
string
audit_policy_changes
string
audit_subcategory
string
auth_package
string
code
integer
command
string
company
string
correlation
string
current_directory
string
description
string
display_name
string
dns_host
string
dns_results
string
dns_status
integer
driver
string
dst_host
string
dst_ip
string
dst_ipv6
boolean
dst_port
integer
dst_port_name
string
domain
string
elevated
string
exe
string
execution_pid
integer
execution_tid
integer
expiration
string
file_version
string
guid
string
hash
string
home_directory
string
home_path
string
impersonation
string
integrity_name
string
integrity_sid
string
key_length
integer
linked_logon_id
integer
lm_package_name
string
audit_guid
string
logon_hours
string
logon_process
string
logon_type
string
logon_title
string
logout
string
new_reg_key
string
new_state
string
new_time
string
new_uac
string
new_user_name
string
new_value
string
net_conn_initiated
boolean
notification_package
string
old_time
string
old_uac
string
parent_command
string
parent_guid
string
parent_name
string
password_last_set
string
pid
integer
pipe_name
string
ppid
integer
primary_group_id
string
principal_name
string
privileges
string
product
string
profile_path
string
protocol
string
record_number
integer
restricted_admin
string
reg_event
string
sam_account
string
script_path
string
security_package
string
service_account
string
service_file
string
service_name
string
service_start
integer
service_type
integer
session
uint32**
sid
string
sid_history
string
signature
string
signature_validity
string
signed
boolean
special_groups
string
spn
string
src_host
string
src_ip
string
src_ipv6
string
src_log
string
src_port
integer
src_port_name
string
start_addr
string
start_func
string
start_module
string
status
string
status_string
string
subject_domain
string
subject_session
string
subject_user
string
subject_sid
string
summary
string
target_device
string
target_domain
string
target_exe
string
target_file
string
target_group
string
target_group_id
string
target_guid
string
target_outbound_domain
string
target_outbound_user
string
target_pid
integer
target_reg_key
string
target_sid
string
target_user
string
target_server
string
target_server_info
string
target_session
string
terminal_session
string
thread_id
string
timestamp
string
token_elevation_type
string
trace
string
transmitted_services
string
tty
string
uac
string
user
string
user_parameters
string
virtual
string
win_event_id
uint16***
wmi_consumer
string
wmi_consumer_type
string
wmi_event
string
wmi_filter
string
wmi_name
string
wmi_namespace
string
wmi_operation
string
wmi_query
string
workstation
string
*The field is searchable with Threat Stack Event Search.
** uint32 is an unsigned integer with 32 bits, which means you can represent 2^32 numbers.
*** uint16 is an unsigned integer with 16 bits, which means you can represent 2^16 numbers.
Related Articles
Data Portability
View ArticleYou can update a ruleset in the Threat Stack Cloud Security Platform (CSP). Locate the rule by either navigating to the Rules tab or the Alerts tab.
Note
If you are looking to create a ruleset, please review the Rule Creation Overview article.
Updating Through the Rules Tab
Navigate to the Rules tab and select the rule you would like to update.
How do I Suppress an Alert?
The Details pane displays on the right side. You can update the following:
The rule name
The alert title
The alert description
The aggregate fields
The frequency of triggering an alert
Click Update Rule to register your changes.
Click the Filter link to display the rule filter settings. You can also update your deployment and suppression settings.
To add a new suppression, click the New Suppression button. For additional information, please review the How do I Suppress an Alert? article.
After making your selections, make sure to register your changes.
The updates to the ruleset will be displayed in the Rules tab.
Updating Through the Alerts Tab
Navigate to the Alerts tab. Locate the alert associated with the rule you would like to update.
Note
In this example, the "User activity (Logins)" alert was selected.
Click the View/Edit Rule link.
The Edit Rule dialog displays. Within the Details pane, you can update the following:
The severity of the alert
The rule name
The alert title
The alert description
The aggregate fields
The frequency of triggering an alert
Note
In this example, a host rule is being updated.
You can also update other settings for deployment, rule filter and suppression by clicking their respective tabs.
To add a new suppression, select the Suppressions tab and click the New Suppression button. For additional information, please review the article.
After making your selections, make sure to register your changes.
The ruleset is updated and your changes are displayed in the Threat Stack CSP.
View ArticleIf you have configured File Integrity Monitoring (FIM) but are unable to view events that trigger alerts in Threat Stack, consider these troubleshooting suggestions or contact support.
Ensure your server is assigned a ruleset.
Confirm the specific rule is enabled.
Confirm the rule is monitoring the expected directory and event type.
Ensure no suppression is preventing the alert from triggering.
Verify the rule reached the Agent.
Verify FIM events are appearing on the Events page.
Ensure the server does not run CentOS or RHEL 6 ( RHEL 6 and CentOS specific FAQ).
Is the Ruleset Applied to the Server?
You can ensure Threat Stack is monitoring the right server.
In the left navigation pane, click the Servers tab.
Select the server from the list.
Verify the correct ruleset displays in the Summary pane.
Note
In this example, a Base Rule Set was assigned to the server named "instance-1".
Confirm the Rule is Enabled
Navigate to the ruleset and ensure the rule is enabled.
In the left navigation pane, click the Rules tab.
Note
You can also navigate to the ruleset from the Servers page.
Select a ruleset from the list.
Note
In this example, the Base Rule Set was selected.
Click the Show More link to display additional rules.
Select a rule from the list.
Note
In this example, the Files: Secret File Opens rule is selected.
Confirm the rule is enabled.
Note
Disabled rules will be grayed out and listed at the bottom of the ruleset they belong to.
Confirm the Rule is Monitoring the Expected Directory and Event Type
You can inspect the rule and confirm the rule monitors the expected directory and event type(s).
In the left navigation pane, click the Rules tab.
Note
You can also navigate to the ruleset from the Servers page.
Select a ruleset from the list.
Note
In this example, the Base Rule Set was selected.
Click the Show More link to display additional rules.
Select a rule from the list.
Note
In this example, the Files: Secret File Opens rule is selected.
Click the File Paths link.
In the right view pane, the File Paths to Monitor screen is displayed. Confirm the rule is monitoring the expected directory and event type(s), by reviewing the File Integrity Paths field and the Events To Monitor field.
Confirm No Suppressions are Preventing Alerts fromTriggering
There could be a suppression preventing an alert from displaying an event. You can confirm whether a suppression is enabled within a rule.
In the left navigation pane, click the Rules tab.
Note
You can also navigate to the ruleset from the Servers page.
Select a ruleset from the list.
Note
In this example, the Base Rule Set was selected.
Click the Show More link to display additional rules.
Select a rule from the list.
Note
In this example, the Files: Secret File Opens rule is selected.
Click the Suppressions link.
In the right view pane, the Suppressions screen is displayed. Review the related suppressions and confirm they do not interfere with your ability to generate an alert.
Confirm the Rule Reached the Agent
Connect to your instance.
Navigate to the following directory:/opt/threatstack/etc/.
Open the tsfim.config.json file.
Within this file, under the watchers key find the directories key.
Its value should be a list of the monitored directories.
Confirm your directory displays on this monitored list.
Note
If you choose to monitor an individual file instead, or in addition to a directory, then it will display in the files key instead of the directories key.
Example
The Files: Secret File Opens" rule has Threat Stack monitor the "/fimtesting/" and "/home/ubuntu/.aws/" directories. Threat Stack does not monitor any individual files because the rule does not call for monitoring.
Confirm Events are Generated and Searchable in Threat Stack
You can confirm whether the right events are searchable in the Threat Stack Cloud Security Platform (CSP).
In the left navigation pane, click the Events tab. All raw events are displayed.
In the Search field, enter the following:
event_type = "file"
Note
File refers to a FIM event in the Threat Stack CSP.
Click the Date and Time drop-down menu.
The date and time dialog displays. Click the Quick Jump link.
Select your desired time period from the available options.
Note
Selecting the time period triggers the search in Threat Stack.
A list of events is displayed.
Note
If no search results display, ensure there is no misspelling in your search criteria or select a different time frame.
View ArticleThreat Stack user accounts lock out if the user types their password incorrectly too many times. If you are the Threat Stack organization owner, then you receive an email notifying you that a users account is locked out. If you decide not to unlock the account, then you can revoke the account instead. You sign into the Threat Stack Cloud Security Platform (CSP) to revoke the account.
Log into Threat Stack.
In the left navigation pane, click the Settings tab. The Settings page displays.
Click the Users tab. The Users page displays.
In the row for the user account to revoke, in the Options column, click the Revoke Access button. A notification message displays.
Click the Yes, Revoke Access button. The user account no longer has access to Threat Stack and no longer displays on the Users page.
View ArticleEvents that enter the Threat Stack Cloud Security Platform (CSP) are keyword searchable. You can use any field in the event's metadata as a search keyword. You can also use a predetermined set of operators to combine keywords into a refined search query.
The following sections list keyword searchable fields by event type and the operators you can use to refine search queries. For more information on searching for events, see Search for Events.
Audit Events: Supported Keywords
Field Name
Field Definition
Subfield Name
event_type
The overarching type of the event, as defined by Threat Stack.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
arguments
List of all arguments in the event.
auid
The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.
command
The command run that triggered the event.
connection
A description of the socket connection made to or from the monitored instance.
addr
dst_addr
dst_port
port
src_addr
src_port
version
containerId
If the event is from a container, then the ID of the container from which the event triggered.
containerImage
If the event is from a container, then the title of the container image from which the event triggered.
cwd
The path to the directory that invoked the system call that triggered the event.
egid
The effective group ID of the user who triggered the event.
euid
The effective user ID of the user who triggered the event.
eventId
The Threat Stack-generated ID of the event.
exe
The path to the executable used to trigger the event.
exit
The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.
exit_status
The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.
code
termination
fd
If set, then the file descriptor of the socket that opened for a network connection.
gid
The group ID of the user who triggered the event.
group
The group of the user who triggered the event.
header
The information in the header of the audit message that triggered the event.
id
milliseconds
timestamp
timestamp
The UNIX timestamp of when the event triggered.
is_agent_2
Indicated whether or not the Agent sending the event is a Threat Stack version 1.x Agent event or a Threat Stack version 2.x Agent event.
loginuid
The user ID logged in at the time the event triggered.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
path
The information about any paths which were passed as an argument to the system call that triggered the event.
pid
The process ID attached to the event, as reported by your operating system (OS).
pod_name
If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.
pod_uid
If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.
ppid
The parent process ID attached to the event, as reported by your OS.
rule_name
The name of the Threat Stack rule applied to the event.
session
The Shell session from which the event triggered.
success
A Boolean value that indicates whether or not the action that triggered the event was successful.
syscall
The type of system call sent to the kernel.
tty
The terminal from which the system call was invoked.
uid
The user ID of the user who triggered the event.
user
The username of the user who triggered the event.
CloudTrail Events: Supported Keywords
Field Name
Field Definition
Subfield Name
Subfield Name
Subfield Name
Subfield Name
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
timestamp
The UNIX timestamp of when the event triggered.
_insert_time
The UNIX timestamp of the time the event reached the edge of the Threat Stack CSP.
event_type
The overarching type of the event, as defined by Threat Stack.
eventVersion
The version of the log event format.
userIdentity
Information about the user that made the request.
type
userName
principalId
arn
accountId
accessKeyId
sessionContext
attributes
creationDate
mfaAuthenticated
invokedBy
sessionIssuer
webIdFederationData
federatedProvider
attributes
eventSource
The service to which the request was made. The format is typically the short form of the service name + .amazonaws.com, such as cloudformation.amazonaws.com.
eventSourceType
eventName
The requested action. The value returned depends on the actions available through the API for the service.
accountId
The account that owns the entity that granted permissions for the request. If the request was made with temporary security credentials, then this is the account that owns the IAM user/role used to obtain credentials.
arn
awsRegion
The AWS region to which the request was made.
userAgent
The agent through which the request was made, such as the AWS Management Console, an AWS service, the AWS SDKs, or the AWS CLI.
bucketName
error
errorCode
If the request returns an error, then the AWS service error number.
errorMessage
If the request returns an error, then the AWS service error description.
responseElements
The response element for actions that make changes, such ascreate,delete, orupdate.
assumedRoleUser
arn
assumedRoleId
credentials
accessKeyId
requestParameters
The parameters sent with the request. The parameters are documented in each AWS service's API documentation.
groupId
ipPermissions
items
fromPort
ipProtocol
toPort
ipv6Ranges
items (This field is a list of IP addresses)
roleSessionName
additionalEventData
Additional information about the event that is not part of the request or the response.
requestId
The value that identifies the request. The serviced called generates this value.
eventId
The Threat Stack-generated ID of the event.
eventType
The ID of the type of the event that triggered the event.
apiVersion
The API version associated with the AwsApiCall eventType value.
arnRole
accessKey
cidrIP
consoleLogin
managementEvent
A Boolean value that indicates whether or not the event is a management event.
MFAUsed
readonly
A Boolean value that indicates whether or not the event is a read-only event.
resourceName
resourceType
resources
A list of resources accessed in the event.
ARN
accountId
type
recipientAccountID
The account ID that received the event.
serviceEventDetails
The service event, including the trigger for the event and the result.
sharedEventID
The GUID generated by CloudTrail to uniquely identify CloudTrail events from the same AWS action that is sent to different AWS accounts.
subnetId
iamInstanceProfileArn
iamInstanceProfileId
ip
imageId
keyId
sourceIPAddress
The IP address from which the request was made.
permission
profileId
policyArn
feed
user
The username of the user who triggered the event.
userType
vpcID
The VPC endpoint in which requests were made from a VPC to another AWS service.
File Integrity Monitoring (FIM) Events: Supported Keywords
Field Name
Field Definition
Subfield Name
event_type
The overarching type of the event, as defined by Threat Stack.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
arguments
List of all arguments of the command executed that resulted in the filesystem event that triggered the event.
auid
The audit user identification (ID) of the user who triggered the event. This ID is assigned at user login and is inherited by every process, even when the user's identity changes.
command
The command run that triggered the event.
containerId
If the event is from a container, then the ID of the container from which the event triggered.
containerImage
If the event is from a container, then the title of the container image from which the event triggered.
eventId
The Threat Stack-generated ID of the event.
events
The strings that represent the type of event that occurred, such asACCESS, CLOSE, DELETE, MODIFY, and so on.
exe
The path to the executable used to trigger the event.
exit
The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.
filename
The name of the file that triggered the event.
gid
The group ID of the user who triggered the event.
group
The group of the user who triggered the event.
timestamp
The UNIX timestamp of when the event triggered.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
pid
The process ID attached to the event, as reported by your operating system (OS).
pod_name
If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.
pod_uid
If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.
ppid
The parent process ID attached to the event, as reported by your OS.
rule_id
The id of the rule applied to the event.
session
The Shell session from which the event triggered.
tty
The terminal from which the system call was invoked.
uid
The user ID of the user who triggered the event.
user
The username of the user who triggered the event.
Kubernetes Audit Events: Supported Keywords
Field Name
Field Definition
Subfield Name
Subfield Definition
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
event_type
The overarching type of the event, as defined by Threat Stack.
action
The type of event.
eventId
The Threat Stack-generated ID of the event.
timestamp
The UNIX timestamp of when the event triggered.
name
The namespace in which the object exists.
node_name
The name of the node (server) on which the event triggered.
namespace
The Kubernetes namespace in which the event triggered.
resource
The object on which the event triggered.
name
type
namespace
type
The type of record, as reported by either auditd or the OS.
Kubernetes Config Events: Supported Keywords
Field Name
Field Definition
Subfield Name
Subfield Definition
Subfield Name
Subfield Definition
Subfield Name
Subfield Definition
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
event_type
The overarching type of the event, as defined by Threat Stack.
action
The type of event.
eventId
The Threat Stack-generated ID of the event.
timestamp
The UNIX timestamp of when the event triggered.
name
The namespace in which the object exists.
namespace
The Kubernetes namespace in which the event triggered.
type
The type of record, as reported by either auditd or the OS.
spec
The configuration of the object.
role_bindings
targets
name
type
namespace
role_name
role_type
role_policies
verbs
api_groups
resources
resource_names
Linux Host Events: Supported Keywords
Field Name
Field Definition
Subfield Name
event_type
The overarching type of the event, as defined by Threat Stack.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
arguments
List of all arguments in the event.
auid
The audit user identification (ID) of the user who triggered the event. This ID is assigned at user login and is inherited by every process, even when the user's identity changes.
caddr
The address in memory from which the symbol for the event loads.
comment
A text comment that attempts to provide additional information to the preloaded information for the event.
eventId
The Threat Stack-generated ID of the event.
exe
The path to the executable used to trigger the event.
function
The symbol found to be overloaded.
group
The group of the user who triggered the event.
timestamp
The UNIX timestamp of when the event triggered.
level
The level value from the rule applied to the event.
library
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
originalLibrary
The shared object file from which the symbol for the event should have loaded.
overridingLibrary
The shared object file from which the symbol for the event currently loads.
pid
The process ID attached to the event, as reported by your operating system (OS).
raddr
The address of the real symbol for the event that should have been loaded.
session
The Shell session from which the event triggered.
sigid
The rule ID of the rule applied to the event.
src_ip
If set, then indicates the source IP address of the action that triggered the event.
subj
uid
The user ID of the user who triggered the event.
user
The username of the user who triggered the event.
Login Events: Supported Keywords
Field Name
Field Definition
Subfield Name
event_type
The overarching type of the event, as defined by Threat Stack.
address
The IP address from which the user who triggered the event originated.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
arguments
List of all arguments in the event.
auid
The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.
command
The command run that triggered the event.
containerId
If the event is from a container, then the ID of the container from which the event triggered.
containerImage
If the event is from a container, then the title of the container image from which the event triggered.
eventId
The Threat Stack-generated ID of the event.
exe
The path to the executable used to trigger the event.
host
timestamp
The UNIX timestamp of when the event triggered.
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
pid
The process ID attached to the event, as reported by your operating system (OS).
pod_name
If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.
pod_uid
If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.
session
The Shell session from which the event triggered.
uid
The user ID of the user who triggered the event.
user
The username of the user who triggered the event.
Threat Intelligence (ThreatIntel) Events: Supported Keywords
Field Name
Field Definition
Subfield Name
event_type
The overarching type of the event, as defined by Threat Stack.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
arguments
List of all arguments in the event.
auid
The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.
command
The command run that triggered the event.
connection
The description of the socket connection made to or from the monitored instance.
addr
dst_addr
dst_port
port
src_addr
src_port
containerId
If the event is from a container, then the ID of the container from which the event triggered.
containerImage
If the event is from a container, then the title of the container image from which the event triggered.
cwd
The path to the directory that invoked the system call that triggered the event.
egid
The effective group ID of the user who triggered the event.
euid
The effective user ID of the user who triggered the event.
eventId
The Threat Stack-generated ID of the event.
exe
The path to the executable used to trigger the event.
exit
The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.
exit_status
The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.
code
termination
fd
If set, then the file descriptor of the socket that opened for a network connection.
gid
The group ID of the user who triggered the event.
group
The group of the user who triggered the event.
header
The information in the header of the audit message that triggered the event.
id
milliseconds
timestamp
timestamp
The UNIX timestamp of when the event triggered.
is_agent_2
Indicated whether or not the Agent sending the event is a Threat Stack version 1.x Agent event or a Threat Stack version 2.x Agent event.
loginuid
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
path
The information about any paths which were passed as an argument to the system call that triggered the event.
pid
The process ID attached to the event, as reported by your operating system (OS).
pod_name
If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.
pod_uid
If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.
ppid
The parent process ID attached to the event, as reported by your OS.
rule_name
The name of the Threat Stack rule applied to the event.
session
The Shell session from which the event triggered.
success
A Boolean value that indicates whether or not the action that triggered the event was successful.
syscall
The type of system call sent to the kernel.
threatintelEventId
The ID of the event.
threatintel_reason
The reason the IP address is marked as malicious.
threatintel_source
The source of information used to determined that the IP address is malicious.
threatintel_type
The hardcoded value of the IP address.
tty
The terminal from which the system call was invoked.
type
The type of record, as reported by either auditd or the OS.
uid
The user ID of the user who triggered the event.
user
The username of the user who triggered the event.
Windows Events: Supported Keywords
Field Name
Field Definition
organization_id
The ID that describes the Threat Stack customer organization that reported the event.
agent_id
The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.
event_type
timestamp
The time at which the event triggered.
addr
command
The cli command that triggered the event.
correlation
The GUID of the activity that triggered the event.
dns_host
The name of the computer as registered in DNS.
dst_host
Sysmon: The hostname of the network connection's destination.
dst_ip
Sysmon: The destination IP address of the network connection.
dstIpv6
Sysmon: A Boolean value which indicates whether or not the IP address in an IPv6 address.
dst_port
Sysmon: The port used by the network connection's destination.
domain
eventId
The Threat Stack-generated ID of the event.
exe
The filename of the event's triggering or target application.
guid
Sysmon: The GUID of a newly-created process. A unique universal identifier.
hash
Sysmon: A hash value.
linked_logon_id
The ID of a paired login.
logon_process
logon_type
Login type as an INT.
parent_command
Sysmon: The cli command used to invoke a new event's parent.
parent_guid
Sysmon: The GUID of a new process's parent.
parent_name
The name of a new process's parent.
pid
The ID attached of an event's triggering or newly created process.
ppid
Used for events that create new processes.
reg_event
Sysmon: The type of operation performed on the target registry key.
sam_account
The SAM account associated with the event, usually account management.
sid
A security identifier.
signature
Sysmon: The signature of a driver.
signature_validity
Sysmon: Integrity of a driver's signature.
signed
A Boolean value that indicates whether or not the driver is signed.
src_ip
Sysmon: The IP address of a network connection source.
src_ipv6
Sysmon: A Boolean value that indicates whether or not a network connection's IP address is IPv6.
src_port
Sysmon: The source's port in a network connection.
target_exe
Sysmon: The executable affected by this event.
target_file
target_guid
Sysmon: The GUID of a target process.
target_reg_key
Sysmon: The registry key affected by this event.
target_user
Sysmon: The username of the account affected by this event.
user
The name of the user who triggered the event.
win_event_id
Supported Operators
Operator
Operator Definition
Example
=
include anything that exactly matches the keyword
exe = "/bin/ls"
!=
exclude anything that exactly matches the keyword
tty != NULL
<
include anything fewer than the keyword
pid < 999
<=
include anything fewer than or equal to the keyword
pid <= 1000
>
include anything greater than the keyword
pid > 999
>=
include anything greater than or equal to the keyword
pid >= 1000
like
include anything that matches a string within the keyword
arguments like "BECOME-SUCCESS"
and &&
include anything that matches both the first condition and the second condition of the query
tty != NULL and tty != "" tty != NULL && tty != ""
or ||
include anything that matches either the first condition or the second condition of the query
tty != NULL or tty != "" tty != NULL || tty != ""
Related Articles
Introduction to Events
Overview: Events Feature
All Raw Events Tab
My Event Queue Tab
Search for Events
View ArticleOverview
This document describes the steps to re-register an Agent not displaying in the Threat Stack Cloud Security Platform (CSP).
Tip
If you need to re-register multiple Agents, Threat Stack recommends re-registering one Agent first to ensure the process works as expected. You may then re-register remaining Agents in parallel.
Linux Agent 1.x Series
If you log into the Threat Stack CSP and the Servers pagedoes not display the expected number of servers, then you may need to re-register your Agent(s). If you see a "Agent has been revoked. Shutting down" message in /opt/threatstack/cloudsight/logs/cloudsight.log, then you need to re-register your Agent.
Prerequisites
Administrator access to your Amazon Web Service (AWS) account
Access to the Threat Stack console
Your deployment key, which can be found in Settings > Application Keys
Instructions
In the Command Line, type the following command and press ENTER:
sudo cloudsight stop
Type the following command and press ENTER:
sudo rm /opt/threatstack/cloudsight/config/.secret
Do one of the following:
To re-register your Agent with the Threat Stack Base Rule Set, type the following command and press ENTER:
sudo cloudsight setup --deploy-key=<your deploy key>
Replace <your deploy key> with your deployment key.
To re-register your Agent with a different Threat Stack ruleset, type the following command and press ENTER:
sudo cloudsight setup --ruleset=<ruleset name> --deploy-key=<your deploy key>
Replace <your deploy key> withyour deployment key. Replace<ruleset name> with the Threat Stack Ruleset name, such as HIPAA.
Note
You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.
Type the following command and press ENTER:
sudo cloudsight start
Linux Agent 2.x Series
If you log into the Threat Stack CSP and the Servers pagedoes not display the expected number of servers, then you may need to re-register your Agent(s). If you run the sudo tsagent status command and receive a "1 tsagent: Agent is revoked" message, then you need to re-register your Agent.
Prerequisites
Administrator access to your Amazon Web Service (AWS) account
Access to the Threat Stack console
Your deployment key, which can be found in Settings > Application Keys
Your AWS hostname
Instructions
Instructions for a Non-revoked Agent
In the Command Line, type the following command and press ENTER:
sudo systemctl stop threatstack
Type the following command and press ENTER:
sudo tsagent setup --deploy-key=<your deploy key> --ruleset=Base Rule Set --hostname=<your hostname>
Replace <your deploy key> with your deployment key. Replace <your hostname>with your AWS hostname.
Note
You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.
Type the following command and press ENTER:
sudo systemctl start threatstack
Instructions for a Revoked Agent
In the Command Line, type the following command and press ENTER:
sudo systemctl stop threatstack
Type the following command and press ENTER:
sudo rm /opt/threatstack/etc/tsagentd.cfg
Type the following command and press ENTER:
sudo tsagent setup --deploy-key=<your deploy key> --ruleset=Base Rule Set --hostname=<your hostname>
Replace <your deploy key>with your deployment key. Replace <your hostname>with your AWS hostname.
Note
You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.
Type the following command and press ENTER:
sudo systemctl start threatstack
View ArticleOnce you log into Threat Stack Application Security (AppSec) Monitoring, you download the microagent, run the installer, and add one line of code to your application.
Download Threat Stack AppSec
You download Threat Stack AppSec installer from AppSec Monitoring in the Threat Stack Cloud Security Platform (CSP).
Note
If your software engineers do not have access to the Threat Stack CSP, then give them one of the following links to download the Threat Stack AppSec installer:
https://pkg.threatstack.com/appsec/node/bluefyre-agent-node-latest.tgz.
.
In the left navigation bar, select the Applications tab. In the right view pane, the AppSec Monitoring page displays.
Select a project and click theAgents button. The Agents screen displays.
Click the Download Agent button.
here
The Download Agent screen displays.
In the type of microagent you want to download, click the Download button. The Threat Stack AppSec installer downloads.
Open the Command Line window and run one of the following command to verify the integrity of the download:
Node.js:
{{shasum -a 256 bluefyre-agent-node.tgz
a70959f1259e425195ad0fb21359c41b36a25bb3d6f1438e4a16b1947c243e69= bluefyre-agent-node-1.2.18.tgz }}
Python
{{shasum -a 256 bluefyre_agent_python.tgz
02546ac9f08dce554adb91cd0fe16fefbe268e2490e36b10ad2cb738afdd3c92 ./bluefyre_agent_python-0.0.8-cp27-cp27m-linux_x86_64.whl
a3ad218939482343fae5703f0452e840d56eefc0d54bdd1fdf71e1a10f57861d ./bluefyre_agent_python-0.0.8-cp27-cp27mu-linux_x86_64.whl
1e695d5d067fc93cefd1b8162504192072df9bf8e6bc118dd1579768be057da4 ./bluefyre_agent_python-0.0.8-cp34-cp34m-linux_x86_64.whl
3e71e861060eaf0053425a9183672d34588f672264db09188e77d429af7e9959 ./bluefyre_agent_python-0.0.8-cp35-cp35m-linux_x86_64.whl
82b6e48dcd8735abcc949f054d654318607b240789ee28d683bf615c53cc75fb ./bluefyre_agent_python-0.0.8-cp36-cp36m-linux_x86_64.whl
b61c8c1aa6b59d3b9373112e9ea38b4ce4f9eeef855d990e02204b91a5108f31 ./bluefyre_agent_python-0.0.8-cp37-cp37m-linux_x86_64.whl
1ec2aeaceaa7c24766bb8a468aa28c0a0307b6b7d0265f843af753e586cabd8a ./bluefyre_agent_python-0.0.8.tar.gz
}}
Install Threat Stack AppSec in Your Application Build Package
You can install Threat Stack AppSec in both Node.js and Python applications.
Node.js
Open the Command Line window and go to your Node application.
Run the following command:
npm install ./bluefyre-agent-node-x.x.x.tgz
Threat Stack AppSec installs.
Python
Run Application Locally
Install a virtual environment, such as venv and Python3.7.
Open the Command Line window and go to your Python application.
Do one of the following:
If you use an Linux distribution or a Windows operating system (OS), then use the source distribution to install the application:
python --versionpip install bluefyre_agent_python-latest.tar.gz
If you use an Ubuntu distribution, then use the wheel files to install the application:
python --versionpip install bluefyre_agent_python-latest-cp37-cp37m-linux_x86_64.whl
Threat Stack AppSec installs.
Run Application in Production
If running a production Django app, install the AppSec agent so that it works with a WSGI server, such as gunicorn or uwsgi.
gunicorn
BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn web_project.wsgi -b :5001
gunicorn with a different worker class thread, such as gevent and three workers:
BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn --worker-class=gevent --worker-connections=1000 --workers=3 web_project.wsgi 0.0.0.0:5000
Threat Stack AppSec installs.
Add Threat Stack AppSec to Your Application (Node.js Only)
Add a single line of code to your Node.js application to include Threat Stack AppSec as a dependent library.
Open the Command Line window and go to your Node application.
Go to the entry point of your application, typically the index.js or server.js file.
In the first line of the file, add the following command:
var agent = require('bluefyre-agent-node')
Save the file. Threat Stack AppSec now sends information back to the server when your application runs.
Set Microagent ID and Run Application
Once you configure your Threat Stack AppSec project(s) and microagent(s), add a microagent ID to your applications environment. Threat Stack AppSec displays proactive risk identification(s) from your code base and real time attack alerts in the selected microagent.
Node.js
Open the Command Line window and go to your Node application.
Do one of the following:
Add the following environment variable, which associates your Threat Stack AppSec microagent ID with your application:
BLUEFYRE_AGENT_ID="YOUR_AGENT_ID_GOES_HERE" npm start
Replace Your_Agent_ID_Goes_Here with your microagent ID number. Instructions on how to find the microagent ID number are .
Now, when your application starts, risk factors in your applications code base and detected attacks display in the selected microagent.
Create a file in the applications root directory called bluefyre.json and include the following commands:
{
"agent_id": "YOUR_AGENT_ID"
"Other Optional Arguments": VALUE
}
Replace Other Optional Arguments with one or more of the following commands:
To automatically block detected SQL injection attacks:
BLUEFYRE_BLOCK_SQLI=true
To automatically block cross-site scripting attacks:
BLUEFYRE_BLOCK_XSS=true
To exclude specific fields from scanning:
BLUEFYRE_DROP_FIELDS ="list of fields"
Replace list of fields with field names.
Python
Run Application Locally
Open the Command Line window.
To start a Django web application on port 5000, run the following command:
BLUEFYRE_AGENT_ID=12323231313 bluefyrectl execProgram python minimal.py runserver --noreload 0.0.0.0:5000
Optionally, specify one or more of the additional variables:
To automatically block detected SQL injection attacks:
BLUEFYRE_BLOCK_SQLI=true
To automatically block cross-site scripting attacks:
BLUEFYRE_BLOCK_XSS=true
To exclude specific fields from scanning:
BLUEFYRE_DROP_FIELDS ="list of fields"
Replace list of fields with field names.
Run Application in Production
Open the Command Line window.
To start in gunicorn with a different worker class thread, such as gevent and three workers, run the following command:
BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn --worker-class=gevent --worker-connections=1000 --workers=3 web_project.wsgi 0.0.0.0:5000
Optionally, specify one or more of the additional variables:
To automatically block detected SQL injection attacks:
BLUEFYRE_BLOCK_SQLI=true
To automatically block cross-site scripting attacks:
BLUEFYRE_BLOCK_XSS=true
To exclude specific fields from scanning:
BLUEFYRE_DROP_FIELDS ="list of fields"
Replace list of fields with field names.
Troubleshooting Threat Stack AppSec
As soon as your application is running, view the Agent Timeline page. The Agent Timeline page displays some information in the Environment pane, and the Events in last 24h" pane begins to increment. If you do not see this information, the microagent may not be properly reporting to the AppSec Monitoring service.
To troubleshoot the issue, you can run in a debug mode and view details.
Stop the application.
Open the Command Line window.
Restart the application with one of the following commands:
Node.js
DEBUG='bluefyre:*' npm start
Python Django
# django
DEBUG=true BLUEFYRE_AGENT_ID="23423432424234" LOGLEVEL=DEBUG bluefyrectl execProgram python manage.py runserver --noreload 0.0.0.0:5001
Python gunicorn
# gunicorn
DEBUG=true BLUEFYRE_AGENT_ID="23423432424234" LOGLEVEL=DEBUG bluefyrectl execProgram gunicorn web_project.wsgi -b :5001
View ArticleIn the Threat Stack Cloud Security Platform (CSP), organization owners and organization users have different privileges. Organization owners have more privileges than organization users. Organization owners and users have the same basic privileges in the Threat Stack CSP, but organization owners exclusively have the following privileges:
Add, revoke, and delete Threat Stack CSP user accounts.
Enable, edit, and delete single sign-on (SSO) integrations with the Threat Stack CSP.
Enable, edit, and delete push notification integrations with PagerDuty.
Reset your organizations deployment key for Agent installation.
Change your organizations settings for auto-dismissal of Severity 3 alerts.
Change your organizations name.
Add or update billing information for the Threat Stack CSP.
Tip
Need a more thorough explanation of the privilege differences between organization owners and users? See this article.
View ArticleIn the Threat Stack Cloud Security Platform (CSP), organization owners and organization users have different privileges. Organization owners have more privileges than organization users. These organization privileges cannot be configured by any Threat Stack CSP account, whether owner or user.
Tip
Just need a quick breakdown of the privilege differences between organization owners and users? See this FAQ.
Navigation Tabs
Organization Owner
Organization User
View the left navigation pane
View the left navigation pane
Switch organizations
Switch organizations
Access the Dashboard tab
Access the Dashboard tab
Access the Config Audit tab
Access the Config Audit tab
Access the Servers tab
Access the Servers tab
Access the Alerts tab
Access the Alerts tab
Access the Events tab
Access the Events tab
Access the Rules tab
Access the Rules tab
Access the Audit Log tab
Access the Audit Log tab
Access the Applications tab
Access the Applications tab
Access the Settings tab
Access the Settings tab
View the top navigation pane
View the top navigation pane
View the title of the currently selected left navigation tab
View the title of the currently selected left navigation tab
View your account avatar
View your account avatar
View the email address associated with your account
View the email address associated with your account
Log out of the Threat Stack CSP
Log out of the Threat Stack CSP
Access the Support menu
Access the Support menu
Open a Support ticket
Open a Support ticket
View the status of the Threat Stack CSP
View the status of the Threat Stack CSP
Access Help and Documentation about the Threat Stack CSP
Access Help and Documentation about the Threat Stack CSP
View the Threat Stack CSP's terms of service
View the Threat Stack CSP's terms of service
View the Threat Stack CSP's privacy policy
View the Threat Stack CSP's privacy policy
Dashboard Tab
Organization Owner
Organization User
Access the Dashboard tab
Access the Dashboard tab
View the New Alerts in the Last 24 Hours pane
View the New Alerts in the Last 24 Hours pane
Access the Alerts tab > Severity 1 tab
Access the Alerts tab > Severity 1 tab
Access the Alerts tab > Severity 2 tab
Access the Alerts tab > Severity 2 tab
View the Vulnerable Servers pane
View the Vulnerable Servers pane
View the Servers tab > Online Servers tab
View the Servers tab > Online Servers tab
View the Coverage Analysis pane
View the Coverage Analysis pane
View the Severity 1 Alerts Generated This Week pane
View the Severity 1 Alerts Generated This Week pane
Access the Alerts tab > Severity 1 tab
Access the Alerts tab > Severity 1 tab
View the Severity 2 Alerts Generated This Week pane
View the Severity 2 Alerts Generated This Week pane
Access the Alerts tab > Severity 2 tab
Access the Alerts tab > Severity 2 tab
Config Audit Tab
Organization Owner
Organization User
Access the Config Audit tab
Access the Config Audit tab
Run a configuration audit assessment
Run a configuration audit assessment
View results of a configuration audit assessment
View results of a configuration audit assessment
Servers Tab
Organization Owner
Organization User
Access the Servers tab
Access the Servers tab
Access the Online Servers tab
Access the Online Servers tab
View servers with out of date Agents
View servers with out of date Agents
View servers with high CVE
View servers with high CVE
Search for servers
Search for servers
View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, uptime, and Agent information
View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, uptime, and Agent information
Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, uptime, or Agent information
Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, uptime, or Agent information
Add Threat Stack Agent series 1.x or 2.x to a server
Add Threat Stack Agent series 1.x or 2.x to a server
Select one or multiple server(s)
Select one or multiple server(s)
Revoke one or multiple server(s)
Revoke one or multiple server(s)
Filter displayed servers by vulnerability severity, AWS EC2 tags, Ruleset, and/or Threat Stack Agent version
Filter displayed servers by vulnerability severity, AWS EC2 tags, Ruleset, and/or Threat Stack Agent version
Access the Offline Servers tab
Access the Offline Servers tab
View servers with out of date (no longer supported) Agents
View servers with out of date (no longer supported) Agents
View servers with high CVE
View servers with high CVE
Search for servers
Search for servers
View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, last seen, and Agent information
View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, last seen, and Agent information
Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, last seen, or Agent information
Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, last seen, or Agent information
Add Threat Stack Agent series 1.x or 2.x to a server
Add Threat Stack Agent series 1.x or 2.x to a server
Select one or multiple server(s)
Select one or multiple server(s)
Revoke one or multiple server(s)
Revoke one or multiple server(s)
Filter displayed servers by CVE, vulnerability severity, or AWS EC2 tags
Filter displayed servers by CVE, vulnerability severity, or AWS EC2 tags
Access the All EC2 Servers tab
Access the All EC2 Servers tab
View non-monitored instances
View non-monitored instances
Search for instances
Search for instances
View whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, and the instance's internal IP address
View whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, and the instance's internal IP address
Sort by whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, or the instance's internal IP address
Sort by whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, or the instance's internal IP address
Filter displayed servers by EC2 monitored state, EC2 key name, and/or EC2 instance type
Filter displayed servers by EC2 monitored state, EC2 key name, and/or EC2 instance type
Access the Vulnerabilities tab
Access the Vulnerabilities tab
View active vulnerabilities
View active vulnerabilities
View vulnerable packages, CVEs, vectors, servers affected, and vulnerability severity
View vulnerable packages, CVEs, vectors, servers affected, and vulnerability severity
Select one or multiple vulnerability(ies)
Select one or multiple vulnerability(ies)
Suppress a vulnerability for business reasons, false positive, compensating control in place, or other
Suppress a vulnerability for business reasons, false positive, compensating control in place, or other
Suppress all vulnerabilities related to a specific CVE for business reasons, false positive, compensating control in place, or other
Suppress all vulnerabilities related to a specific CVE for business reasons, false positive, compensating control in place, or other
Filter vulnerabilities by CVE, package, attack vector, and/or severity level
Filter vulnerabilities by CVE, package, attack vector, and/or severity level
View suppressed vulnerabilities
View suppressed vulnerabilities
View suppressed vulnerability packages, CVEs, date and time of suppression, and reason for suppression
View suppressed vulnerability packages, CVEs, date and time of suppression, and reason for suppression
Select one or multiple suppressed vulnerability(ies)
Select one or multiple suppressed vulnerability(ies)
Remove suppressions from vulnerabilities
Remove suppressions from vulnerabilities
Alerts Tab
Organization Owner
Organization User
Access the Alerts tab
Access the Alerts tab
Access the Alerts Histogram section
Access the Alerts Histogram section
Select a time range / clear the time range on the Alerts Histogram
Select a time range / clear the time range on the Alerts Histogram
Filter alerts by title
Filter alerts by title
Change the displayed number of alerts that match the selected filters
Change the displayed number of alerts that match the selected filters
View alerts by group
View alerts by group
View the number of alerts in a group, the title of the group, and the trend line for those alerts over the previous seven calendar days
View the number of alerts in a group, the title of the group, and the trend line for those alerts over the previous seven calendar days
View subgroups of alerts
View subgroups of alerts
View the number of alerts in a subgroup and the title of the subgroup
View the number of alerts in a subgroup and the title of the subgroup
Select one or multiple subgroup(s)
Select one or multiple subgroup(s)
Dismiss all alerts in a subgroup for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons
Dismiss all alerts in a subgroup for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons
Suppress all alerts in a subgroup
Suppress all alerts in a subgroup
View alerts in a list
View alerts in a list
View an alert's severity, title, and last date and time of the alert
View an alert's severity, title, and last date and time of the alert
Sort alerts by severity, title, or last alert date and time
Sort alerts by severity, title, or last alert date and time
Dismiss an alert for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons
Dismiss an alert for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons
Suppress one or multiple alert(s)
Suppress one or multiple alert(s)
View details of an alert
View details of an alert
View the JSON for an alert
View the JSON for an alert
View or modify the rule associated with the alert
View or modify the rule associated with the alert
View AWS EC2 tags associated with an alert
View AWS EC2 tags associated with an alert
View events that contributed to an alert
View events that contributed to an alert
Filter alerts by rule, by AWS EC2 tag, and/or by Ruleset
Filter alerts by rule, by AWS EC2 tag, and/or by Ruleset
Events Tab
Organization Owner
Organization User
Access the Events tab
Access the Events tab
Access the All Raw Events tab
Access the All Raw Events tab
View a list of supported query keys and operators
View a list of supported query keys and operators
Enter a query to search for specific events
Enter a query to search for specific events
Pick the date and time within which to display events
Pick the date and time within which to display events
Browse events by page
Browse events by page
View event metadata
View event metadata
Add event metadata to a query
Add event metadata to a query
Create a rule from an event
Create a rule from an event
View the JSON for an event
View the JSON for an event
Add an event to the My Event Queue tab
Add an event to the My Event Queue tab
Access the My Event Queue tab
Access the My Event Queue tab
View a list of supported query keys and operators
View a list of supported query keys and operators
Enter a query to search for specific events
Enter a query to search for specific events
Pick the date and time within which to display events
Pick the date and time within which to display events
Browse events by page
Browse events by page
View event metadata
View event metadata
Add event metadata to a query
Add event metadata to a query
View the JSON for an event
View the JSON for an event
Remove an event from the My Event Queue tab
Remove an event from the My Event Queue tab
Rules Tab
Organization Owner
Organization User
Access the Rules tab
Access the Rules tab
Enable / disable Rulesets
Enable / disable Rulesets
View Rulesets
View Rulesets
View Ruleset details
View Ruleset details
View servers using the Ruleset, along with their server name, the specific Ruleset(s) applied, and the last time the server sent a hearbeat
View servers using the Ruleset, along with their server name, the specific Ruleset(s) applied, and the last time the server sent a hearbeat
Search for servers that use the Ruleset
Search for servers that use the Ruleset
Assign / remove servers from the Ruleset
Assign / remove servers from the Ruleset
Add / modify Rulesets
Add / modify Rulesets
Delete Rulesets(except the Base Ruleset, which cannot be deleted)
Delete Rulesets(except the Base Ruleset, which cannot be deleted)
Enable / disable rules
Enable / disable rules
Add rules to the Threat Stack CSP, including Linux Host, FIM, CloudTrail, Threat Intelligence, Windows Host, Kubernetes Audit, and/or Kubernetes Config
Add rules to the Threat Stack CSP, including Linux Host, FIM, CloudTrail, Threat Intelligence, Windows Host, Kubernetes Audit, and/or Kubernetes Config
Clone rules
Clone rules
Add alert triggers to rules
Add alert triggers to rules
Assign severity levels to alert triggers
Assign severity levels to alert triggers
Assign AWS EC2 inclusion / exclusion tags to rules
Assign AWS EC2 inclusion / exclusion tags to rules
Add filters to rules
Add filters to rules
Add suppressions to rules
Add suppressions to rules
Assign / remove rules from a Ruleset
Assign / remove rules from a Ruleset
Modify rules in a Ruleset
Modify rules in a Ruleset
Delete rules from a Ruleset
Delete rules from a Ruleset
Audit Log Tab
Organization Owner
Organization User
Access the Audit Log tab
Access the Audit Log tab
Pick the date and time within which to display audit logs
Pick the date and time within which to display audit logs
Search for specific audit logs
Search for specific audit logs
Browse pages of audit logs
Browse pages of audit logs
View audit logs
View audit logs
View the following information associated with an audit log: email address of the user that triggered the audit action, the source of the audit action, the audit action, a description of the audit action, and the date and time at which the audit action occurred
View the following information associated with an audit log: email address of the user that triggered the audit action, the source of the audit action, the audit action, a description of the audit action, and the date and time at which the audit action occurred
View the JSON for an audit log
View the JSON for an audit log
Settings Tab
Organization Owner
Organization User
Access the Settings tab
Access the Settings tab
General Settings Tab
Organization Owner
Organization User
Access the General Settings tab
Access the General Settings tab
Access the General Settings section
Access the General Settings section
Add or modify the Full Name for the Threat Stack CSP account
Add or modify the Full Name for the Threat Stack CSP account
Add or modify the Organization Name
Enroll in Multi-Factor Authentication
Enroll in Multi-Factor Authentication
Change the current Threat Stack CSP account's password
Change the current Threat Stack CSP account's password
Access the Notification Settings section
Access the Notification Settings section
Enable / disable email alerts
Enable / disable email alerts
Receive daily email reports for: alerts, FIM, vulnerabilities, consolodated compliance information
Receive daily email reports for: alerts, FIM, vulnerabilities, consolodated compliance information
Receive email reports for Configuration Auditing, per assessment
Receive email reports for Configuration Auditing, per assessment
Modify the number of daily email reports to which the Threat Stack CSP account subscribes
Modify the number of daily email reports to which the Threat Stack CSP account subscribes
Access the Alert Settings section
Enable / disable automatic dismissal of Severity 3 alerts
Modify the frequency at which Severity 3 alerts are dismissed
Access the Scheduled Assessments section
Access the Scheduled Assessments section
Enable / disable daily configuration audit assessments
Enable / disable daily configuration audit assessments
Modify the date and time at which configuration audit assessments occur
Modify the date and time at which configuration audit assessments occur
Users Tab
Organization Owner
Organization User
Access the Users tab
Access the Users tab
Send email invitations to people to join your Threat Stack CSP organization
Send email invitations to people to join your Threat Stack CSP organization
View a list of usernames, email addresses, roles, and creation dates for all organization owner and user accounts
View a list of usernames, email addresses, roles, and creation dates for all organization owner and user accounts
Sort by usernames, email addresses, roles, and creation dates for all organization owner and user accounts
Sort by usernames, email addresses, roles, and creation dates for all organization owner and user accounts
Revoke an account's access to your Threat Stack CSP organization
Promote a user account to the organization owner account
Authentication Tab
Organization Owner
Organization User
Access the Authentication tab
Enable / disable Single Sign-On (SSO) for the Threat Stack CSP organization
Modify SSO for the Threat Stack CSP organization
Application Keys Tab
Organization Owner
Organization User
Access the Application Keys tab
Access the Application Keys tab
Access the Deployment Key section
Access the Deployment Key section
View and copy the organization's deployment key
View and copy the organization's deployment key
Reset the organization's deployment key
Access the REST API Key section
Access the REST API Key section
View and copy the organization's REST API key
View and copy the organization's REST API key
Reset the organization's REST API key
Reset the organization's REST API key
View and copy the organization's ID
View and copy the organization's ID
View and copy the user account's user ID
View and copy the user account's user ID
Integrations Tab
Organization Owner
Organization User
Access the Integrations tab
Access the Integrations tab
Access the AWS Accounts section
Access the AWS Accounts section
Add, view, modify, and delete AWS account integrations
Add, view, modify, and delete AWS account integrations
Access the PagerDuty section
Access the PagerDuty section
Add, view, modify, and delete PagerDuty account integrations
Access the Slack section
Access the Slack section
Add, view, modify, and delete Slack account integrations
Add, view, modify, and delete Slack account integrations
Access the VictorOps section
Access the VictorOps section
Add, view, modify, and delete VictorOps account integrations
Add, view, modify, and delete VictorOps account integrations
Access the Webhook API section
Access the Webhook API section
Add, view, modify, and delete webhook integrations
Add, view, modify, and delete webhook integrations
Billing Tab
Organization Owner
Organization User
Access the Billing tab
Access the Billing tab
View payment information
View payment information
Add or update payment information
Public API
REST API V2 information
Organization Owner
Organization User
Access the Rest API V2 overview
Access the Rest API V2 overview
Access the Rest API V2 authentication information
Access the Rest API V2 authentication information
Access the Rest API V2 time range information
Access the Rest API V2 time range information
Access the Rest API V2 pagination information
Access the Rest API V2 pagination information
Access the Rest API V2 rate limit information
Access the Rest API V2 rate limit information
Access the Rest API V2 HTTP status code overview
Access the Rest API V2 HTTP status code overview
Agent Endpoints and Models
Organization Owner
Organization User
Access Agent endpoints and models
Access Agent endpoints and models
Access GET List Agents endpoint
Access GET List Agents endpoint
Access GET Get an Agent endpoint
Access GET Get an Agent endpoint
Access Agent model
Access Agent model
Alert Endpoints and Models
Organization Owner
Organization User
Access Alert endpoints and models
Access Alert endpoints and models
Access Alerts overview information
Access Alerts overview information
Access GET List Alerts endpoint
Access GET List Alerts endpoint
Access GET Get an Alert endpoint
Access GET Get an Alert endpoint
Access GET Get Count of Active Alerts by Severity endpoint
Access GET Get Count of Active Alerts by Severity endpoint
Access GET Get Events for an Alert endpoint
Access GET Get Events for an Alert endpoint
Access POST Dismiss Alerts endpoint
Access POST Dismiss Alerts endpoint
Access Alert model
Access Alert model
Access Alert Severity Count model
Access Alert Severity Count model
Access Dismiss Alert by ID model
Access Dismiss Alert by ID model
Access Dismiss Alert by Query Parameters model
Access Dismiss Alert by Query Parameters model
Audit Log Endpoints and Models
Organization Owner
Organization User
Access Audit Logs endpoints and models
Access Audit Logs endpoints and models
Access GET Audit Logs endpoint
Access GET Audit Logs endpoint
Access Audit Log model
Access Audit Log model
Data Portability Endpoints and Models
Organization Owner
Organization User
Access Data Portability endpoints and models
Access Data Portability endpoints and models
Access GET List S3 Export Enrollment endpoint
Access GET List S3 Export Enrollment endpoint
Access PUT Update S3 Export Enrollment endpoint
Access PUT Update S3 Export Enrollment endpoint
Access DELETE Delete S3 Export Enrollment endpoint
Access DELETE Delete S3 Export Enrollment endpoint
Access S3 Export Enrollment model
Access S3 Export Enrollment model
Access Update S3 Export Enrollment model
Access Update S3 Export Enrollment model
Rulesets and Rules Endpoints and Models
Organization Owner
Organization User
Access Rulesets and Rules endpoints and models
Access Rulesets and Rules endpoints and models
Access Rules and Rulesets overview information
Access Rules and Rulesets overview information
Access GET List Rulesets endpoint
Access GET List Rulesets endpoint
Access GET Get a Ruleset endpoint
Access GET Get a Ruleset endpoint
Access GET List Rules for a Ruleset endpoint
Access GET List Rules for a Ruleset endpoint
Access GET Get a Rule for a Ruleset endpoint
Access GET Get a Rule for a Ruleset endpoint
Access GET List Active Agents for Rulests endpoint
Access GET List Active Agents for Rulests endpoint
Access GET Get Tags for a Rule endpoint
Access GET Get Tags for a Rule endpoint
Access POST Create Ruleset endpoint
Access POST Create Ruleset endpoint
Access POST Create Rules endpoint
Access POST Create Rules endpoint
Access POST Set Tags for a Rule endpoint
Access POST Set Tags for a Rule endpoint
Access PUT Update Ruleset endpoint
Access PUT Update Ruleset endpoint
Access PUT Update Rule endpoint
Access PUT Update Rule endpoint
Access PUT Update Rule Suppression endpoint
Access PUT Update Rule Suppression endpoint
Access DELETE Delete Ruleset endpoint
Access DELETE Delete Ruleset endpoint
Access DELETE Delete Rule endpoint
Access DELETE Delete Rule endpoint
Access IDS Rule model
Access IDS Rule model
Access IDS Rule Response model
Access IDS Rule Response model
Access File Rule model
Access File Rule model
Access File Rule Response model
Access File Rule Response model
Access Kubernetes Audit Rule model
Access Kubernetes Audit Rule model
Access Kubernetes Audit Rule Response model
Access Kubernetes Audit Rule Response model
Access Kubernetes Config Rule model
Access Kubernetes Config Rule model
Access Kubernetes Config Rule Response model
Access Kubernetes Config Rule Response model
Access Ruleset model
Access Ruleset model
Access Windows Rule model
Access Windows Rule model
Access Windows Rule Response model
Access Windows Rule Response model
EC2 Instance Endpoints and Models
Organization Owner
Organization User
Access EC2 Instances endpoints and models
Access EC2 Instances endpoints and models
Access EC2 Instance overview information
Access EC2 Instance overview information
Access GET List AWS EC2 Instances endpoint
Access GET List AWS EC2 Instances endpoint
Access EC2 Instance model
Access EC2 Instance model
CVE Vulnerabilities Endpoints and Models
Organization Owner
Organization User
Access CVE Vulnerabilities endpoints and models
Access CVE Vulnerabilities endpoints and models
Access CVE Vulnerabilities overview information
Access CVE Vulnerabilities overview information
Access GET List Vulnerabilities endpoint
Access GET List Vulnerabilities endpoint
Access GET List Affected Servers by CVE endpoint
Access GET List Affected Servers by CVE endpoint
Access GET List Vulnerabilities by Package endpoint
Access GET List Vulnerabilities by Package endpoint
Access GET List Suppressions with Details endpoint
Access GET List Suppressions with Details endpoint
Access Suppressed CVE Reason model
Access Suppressed CVE Reason model
Access Vulnerable Server model
Access Vulnerable Server model
Access CVE model
Access CVE model
Alert Webhooks API
Organization Owner
Organization User
Access Alert Webhooks API information
Access Alert Webhooks API information
Access Webooks overview
Access Webooks overview
Access Webooks setup information
Access Webooks setup information
Access Webhooks Payload model
Access Webhooks Payload model
Access Webooks security information
Access Webooks security information
Access Webooks retries information
Access Webooks retries information
Access Webook endpoints information
Access Webook endpoints information
View ArticleRelease Announcement
Release Date 11/22/2019
Threat Stack enhanced the following features in the 11/22/2019 API release:
Added the Kubernetes Audit Rule model and the Kubernetes Audit Rule Response model
Added the Kubernetes Config Rule model and the Kubernetes Audit Config Response model
Release Date 10/25/2019
Threat Stack enhanced the following features in the 10/25/2019 API release:
Updated the Webhooks Payloads model to use the correct server_or_region parameter.
Updated the Webhooks Overview to include [IP address]:[port] format.
Release Date 10/21/2019
Threat Stack enhanced the following features in the 10/21/2019 API release:
Added the Windows Rule model.
Added the Windows Rule Response model.
Archived Release Information
2019 API Releases
Release Date 10/10/2019
Threat Stack enhanced the following features in the 10/10/2019 API release:
Updated Create Rule endpoint to use the correct spelling in the example.
Updated Create Rule endpoint to use the correct information in alertDescription.
Release Date 9/17/2019
Threat Stack enhanced the following features in the 9/17/2019 API release:
Updated S3 Export Enrollment endpoint with the correct heading.
Updated Update S3 Export Enrollment endpoint with the correct heading.
Updated Delete S3 Export Enrollment endpoint with the correct heading.
Updated Affected Servers by CVE endpoint with correct spelling.
Release Date 8/9/2019
Threat Stack enhanced the following features in the 8/9/2019 API release:
Updated List All Agents with correct spelling.
Updated Alert Webhooks API Retries with correct spelling.
Release Date 7/16/2019
Threat Stack enhanced the following features in the 7/16/2019 API release:
Updated List All CVEs endpoint with correct spelling.
Release Date 6/28/2019
Threat Stack enhanced the following features in the 6/28/2019 API release:
Updated Dismiss Alert by Query Parameters endpoint with the seven day batch information.
Updated Dismiss Alerts endpoint with the seven day batch information.
Updated Rate Limit information with correct parameter spelling for organizationId.
Release Date 5/8/2019
Threat Stack enhanced the following features in the 5/8/2019 API release:
Updated Webhooks Setup with new IP addresses.
Updated Dismiss Alerts endpoint with the seven day batch information.
Updated Rate Limit information with correct parameter spelling for organizationId.
Release Date 4/4/2019
Threat Stack enhanced the following features in the 4/4/2019 API release:
Added Set Tags for a Rule endpoint.
Updated Get Tags for a Rule endpoint to include exclusion tag parameters.
Release Date 3/18/2019
Threat Stack enhanced the following features in the 3/18/2019 API release:
Updated Dismiss Alert endpoint
Added note to include either a severity, ruleId, or agentId when you dismiss alerts by query, or you receive a 400 error message
dismissReason parameter now displays the correct capitalization for allowed values
Updated Create Rule Set and Update Rule Set endpoints' Request Bodies with the correct `ruleIds` parameter
Release Date 2/13/2019
Threat Stack enhanced the following features in the 2/13/2019 API release:
Added S3 Export Enrollment model
Added Update S3 Export Enrollment endpoint
Release Date 2/11/2019
Threat Stack enhanced the following features in the 2/11/2019 API release:
Added Audit Log model
Updated Audit Logs endpoint to change the userName property to theuserEmailproperty.
View ArticleThe Threat Stack Cloud Security Platform (CSP) automatically assigns your organization a deployment key. Your deployment key is a unique identifier that allows Threat Stack Agents to properly connect to the Threat Stack CSP.
View Your Organizations Deployment Key
Log into the Threat Stack CSP with your organization owner account.
Click the Settings tab. The General Settings tab displays.
Click the Application Keys tab. In the Deployment Key section, your organizations deployment key displays.
Reset Your Organizations Deployment Key
Threat Stack recommends resetting your organizations deployment key if it is exposed to someone outside of your organization, such as a Threat Stack support request in which you include your deployment key. Only organization owners can reset deployment keys.
Log into the Threat Stack CSP with your organization owner account.
Click the Settings tab. The General Settings tab displays.
Click the Application Keys tab. In the Deployment Key section, your organizations deployment key displays.
Click the Reset Deployment Key button. The deployment key resets and changes to a new, unique identifier. Your existing hosts or containers remain connected to the Threat Stack Agent, but any hosts or containers you connect in the future will need to use the new deployment key.
View ArticleThis document describes configuration steps for deploying the Threat Stack host-based Agent in your Amazon Machine Image (AMI) environment.
Agent 1.x Series
Do not run the cloudsight setup command as part of your Amazon Machine Image (AMI) build process. The cloudsight setup command registers the Agent with the Threat Stack service. This registration process assigns a custom token to the Agent. If you include the cloudsight setup command as part of your AMI build process, then the same Agent token will be included on every system deployed using that AMI. This means that multiple Agents will report as a single Agent in the Threat Stack Cloud Security Platform.
To prevent an AMI from including a registered Agent, follow these steps:
As part of your AMI build process, install the Threat Stack Agent using the apt or yum process described in the Deploy the Threat Stack Agent article.
Warning
Do not install the Threat Stack Agent using curl as this registers the Agent.
Create the AMI.
When you deploy the AMI, as part of your node provisioning or as part of the Amazon User Data run the cloudsight setup --deploy-key=<your deploy key> command.
Replace <your deploy key> with your Threat Stack Agent deploy key. When your client boots up it registers and starts the Threat Stack Agent.
Agent 2.x Series
Do not run the tsagent setup command as part of your Amazon Machine Image (AMI) build process. The tsagent setup command registers the Agent with the Threat Stack service. This registration process assigns a custom token to the Agent. If you include the tsagent setup command as part of your AMI build process, then the same Agent token will be included on every system deployed using that AMI. This means that multiple Agents will report as a single Agent in the Threat Stack Cloud Security Platform.
To prevent an AMI from including a registered Agent, follow these steps:
As part of your AMI build process, install the Threat Stack Agent using the apt or yum process described in the Deploy the Threat Stack Agent article.
Warning
Do not install the Threat Stack Agent using curl as this registers the Agent.
Create the AMI.
When you deploy the AMI, as part of your node provisioning or as part of the Amazon User Data run the tsagent setup --deploy-key=<your deploy key> command.
Replace <your deploy key> with your Threat Stack Agent deploy key. When your client boots up it registers and starts the Threat Stack Agent.
Run the systemctl disable threatstack command to ensure the Agent does not attempt to start upon boot up of the instance.
After running the tsagent setup command, update the User Data script to include the systemctl enable threatstack command.
This will ensure the Threat Stack Agent comes up upon subsequent boots.
View ArticleOverview
This document describes the installation and configuration steps for the Threat Stack host-based Windows Agent 2.x series.
Pre-Installation for the Threat Stack Agent
Before you install the Threat Stack host-based Agent, please ensure your environment supports one of the following Windows Server Operating System versions:
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Installing the Threat Stack Agent
Prerequisites
Access to the Threat Stack Cloud Security Platform (CSP).
Ensure you have administrator privileges on the host to perform the installation.
Begin Agent Download
Click the Latest Windows Installer button to download the Agent software.
Once you have downloaded the installer, select one of the installation methods below.
Windows Setup Installation
Navigate to the location of the Threat Stack Cloud Security Agent.msi file.
Double click the file to run it.
A setup wizard window will appear. Click Next to continue with the installation.
Sysmon configuration file
The next screen will display a configuration page, where you can update the following settings:
The default installation location
By default, it is "C:\Program Files\Threat Stack\". Click Change to browse to a location of your choice.
The Threat Stack URL
By default, it is https://app.threatstack.co m.
The Ruleset Name
By default, it is set to Windows Rule Set. You can include multiple rule sets by separating them with a comma.
For example, to include a Windows and a PCI ruleset, enter the following (Do not include the period at the end): Windows Rule Set, PCI Rule Set.
The Deployment Key
A deployment key is required to complete the installation. It is available by logging into your Threat Stack CSP. Navigate to the Settings page and click the Application Keys tab. The key will be displayed under the Deployment Keysection.
By default, the option for Start the services after setup is complete is checked.
You can uncheck this option. The services will be installed butwon'tstart until the host is rebooted.
After entering your organizations deployment key click Next.
Once you have reviewed your selections and are ready to proceed, click Install.
Note
If you have administrator privileges but are not logged into your administrator account, the Install button will show a User Account Control (UAC) shield.
Once the installation is complete, a confirmation message will appear on the screen. Click Finish to close the window.
To confirm the Agent is running on the host, open a command prompt. Enter the following command from the install directory and press ENTER:
tsagent status
Your newly installed server will appear in the Threat Stack CSP on the Serverspage.
Command Line Installation
The Agent can be installed from the command line by either using Windows PowerShell or a Command Prompt. The example below shows the installation process using the Command Prompt.
Open the Command Prompt Window as an administrator.
Enter the following command and press ENTER:
msiexec /qn /i "c:\path\to\threatstack.msi" TSDEPLOYKEY="<DEPLOY_KEY>"
The command line parameters are as follows:
C:\path\to\threatstack.msi - Indicates the location of the msi installer.
For example, if the installer was saved in the Downloads folder on your server, you will enter C:\Users\Administrator\Downloads\threatstack.msi.
TSDEPLOYKEY - It indicates the deployment key used to register with the platform. Replace <DEPLOY_KEY> with your deployment key.
A deployment key is required to complete the installation. It is available by logging into your Threat Stack CSP. Navigate to the Settings page and click the Application Keys tab. The key will be displayed under the Deployment Key section.
TSEVENTLOGLIST (optional) - You can choose to capture System Monitoring (Sysmon) events by adding TSEVENTLOGLIST=Security,Microsoft-Windows-Sysmon/Operationalto the command line.
TSCLOUDURL (optional) - It indicates the URL of the Threat Stack CSP.
By default, it is https://app.threatstack.com.
TSRULESETNAMES (optional) - It indicates the rule set(s) being used.
It defaults to the Windows Rule Set. You can include multiple rule sets by separating them with a comma.
For example, to include a Windows and a PCI rule set, enter the following (Do not include the period at the end): TSRULESETNAMES=Windows Rule Set, PCI Rule Set.
TSSTARTSERVICES (optional) - You can set the Threat Stack Agent (tsagent) service to not start after the installation by adding TSSTARTSERVICES=No to the command line.
The services will start once the host has been rebooted.
INSTALLDIR (optional) - It indicates the installation location.
By default, it is "C:\Program Files\Threat Stack\".
The installation will quietly run in the background. Once complete, it will return a new command line.
To confirm the Agent is running on the host, enter the following command from the install directory and press ENTER:
tsagent status
Your newly installed server will appear in the Threat Stack CSP on the Servers page.
System Monitoring (Sysmon) Installation and Configuration
The Threat Stack Windows Agent leverages Sysmons functionality to focus on security related events. The majority of rules within the Windows Ruleset rely on Sysmon logs. Hence, we recommend installing System Monitoring for optimal performamce of the Windows Agent and its associated rules. For customers who choose not to install Sysmon, the functionality of the Windows Agent becomes very limited. The Agent will still be able to monitor the system (host) via File Integrity Monitoring (FIM) and a subset of events from the Security event log.
Given the volume of information logged by Sysmon, it is best to apply a configuration file that filters out normal operating system processes and common applications that generate vast amounts of data. We recommend using this Sysmon configuration file.
Download Sysmon
Review this Microsoft article for a description of functionality and configuration of Sysmon.
Click the Sysmon Download button to download the Sysmon files.
The downloaded Sysmon.zip file contains 3 files:
Eula.txt - An end user license agreement file.
Sysmon.exe - A 32-bit Sysmon binary used for installing on 32-bit operating systems.
Sysmon64.exe - A 64-bit Sysmon binary used for installing on 64-bit operating systems.
The configuration of Sysmon can be a challenging task due to some of the complexity and logic available to end users. Threat Stack recommends starting with a popular and well commented .
Install Sysmon
Open the Command Line window.
Enter the following command and press ENTER:
Sysmon64.exe accepteula i sysmonconfig-export.xml
Note
The command in this example assumes you downloaded the Sysmon configuration file to the same folder where you extracted your Sysmon.zip file.
Once installed, Sysmon will start writing logs to a newly created Event Log. You can view the log within Event Viewer by navigating to Applications and Services Logs > Microsoft > Windows > Sysmon > Operational.
This log file defaults to a maximum size of approximately 65 megabytes (MB). It will rewrite the oldest logs once this limit is reached.
This default size should be sufficient for most customers.
Configure the Threat Stack Agent
Open the Command Line window.
Enter the following command to enable monitoring of both the Security and Sysmon Event Logs. Then, press ENTER:
tsagent config --set EventLogs Security,Microsoft-Windows-Sysmon/Operational
Enter the following command to restart the Agent. Then, press ENTER.
tsagent restart
View ArticleOrganization owners can configure the automatic dismissal of Severity 3 alerts to suit their organizations needs. All dismissed alerts are accessible in the Threat Stack Cloud Security Platform (CSP).
Enable Automatic Dismissal of Severity 3 Alerts
Log into the Threat Stack CSP with your organization owner account.
Click the Settings tab. The General Settings tab displays.
In the Alert Settings section, slide the Auto-dismiss Severity 3 alerts toggle to the right.
From the Automatically dismiss Severity 3 alerts once they are [X] days old drop-down menu, select the number of days the alert remains in your Threat Stack CSP before automatic dismissal.
Note
The default setting is 30 days. Severity 3 alerts can be dismissed up to 90 days after being triggered.
After making your selection, click the Update Alerts Settings button.
Note
It may take up to 24 hours for the first set of old alerts to be dismissed.
To confirm your selection:
Navigate to the Alerts page.
Select the Sev 3 tab.
Click the expand / collapse button.
The Dismiss pane displays, confirming the automatic dismissal of alerts is enabled.
Disable Automatic Dismissal of Severity 3 Alerts
Log into the Threat Stack CSP with your organization owner account.
Click the Settings tab. The General Settings tab displays.
In the Alert Settings section, slide the Auto-dismiss Severity 3 alerts toggle to the left.
Click the Update Alerts Settings button.
Severity 3 alerts will no longer be automatically dismissed. You can always re-enable this setting.
View ArticleYou can manage users through your Threat Stack Cloud Security Platform (CSP) organization owner account.
Inviting Users
Log into Threat Stack at https://app.threatstack.com.
In the left navigation pane, click Settings. The Settings page displays.
Click the Users tab. The Users page displays.
In the Invite Users section, in the Enter email for invitation field, type the invitees email address.
Click the Send Email button. The user receives an email with instructions on setting up an account with Threat Stack.
https://app.threatstack.com
Removing Users
Log into Threat Stack at .
In the left navigation pane, click Settings. The Settings page displays.
Click the Users tab. The Users page displays.
In the Manage Users section, click the Revoke Access button for the user you would like to remove from your account.
View ArticleIf you want to rename your Threat Stack Cloud Security Platform (CSP) organization for any reason, such as your corporate naming conventions changed, then your organization owner can change your organizations name.
Log into the Threat Stack CSP with your organization owner account.
Click the Settings tab. The General Settings tab displays.
In the Organization Name field, type a new name for your organization.
Click the Update My Profile button. The organization name updates. No additional integrations or settings need to be changed for the update to take effect.
View ArticleYou can create a Kubernetes audit rule in the Threat Stack Cloud Security Platform (CSP).
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Life Cycle of an Alert
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.
The Add Host Rule dialog displays.
Select Kubernetes Audit Rule from the list and click Next: Details to proceed.
The Add Kubernetes Audit Rule dialog displays. You will be able to specify the rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the article.
After making your selection, click Next: Filter.
The Kubernetes Audit Rule Filter pane displays.
After specifying a rule filter, click Create Rule.
The rule will be created and it will be displayed on the Rules page.
View Article
You can create a Kubernetes configuration rule in the Threat Stack Cloud Security Platform (CSP).
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Life Cycle of an Alert
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.
The Add Host Rule dialog displays.
Select Kubernetes Config Rule from the list and click Next: Details to proceed.
The Add Kubernetes Configuration Rule dialog displays. You will be able to specify the rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the article.
After making your selection, click Next: Filter.
The Kubernetes Configuration Rule Filter pane displays.
After specifying a rule filter, click Create Rule.
The rule will be created and it will be displayed on the Rules page.
View Article
Threat Stack collects raw event data from the Agents installed on your machines and delivers it to the Threat Stack Cloud Security Platform (CSP) to be processed. Then, we utilize the Base Ruleset and any rules you created to trigger alerts based on information you want reported.
This article explains the types of event rules and the syntax associated with the events. This information will enable you to search for events more efficiently, and make better suppressions and rule filters to refine the information you see inside of Threat Stack.
Rule Categories
Threat Stack provides the following rule categories based on the following event types.
Types
Event type rules process....
Audit
Syscall events from the audit framework
CloudTrail
AWS CloudTrail events
File
Local file system events for file integrity monitoring
Host
Events triggered from host logs
Windows
Windows Agent events
Login
Local login events
Threat Intel
IP reputation events
Kubernetes Audit
Kubernetes orchestration events
Kubernetes Configuration
Kubernetes configuration events
Search Syntax Best Practices
This section includes best practices that apply to searching across all event types:
The search field is case sensitive.
You can use parentheses when searching multiples of the same:
parameters
key value pairs
The Alert Details section enables a Add to Search option. It adds key values to your search with the correct syntax.
The server syntax for agent is consistent across all event types for rules. It searches for the "hostname".
Note
Threat Stack uses the CloudTrail native case for compatibility reasons. This means the test filter is case sensitive and uppercase letters will cause the test filter not to match even if a suppression or rule filter is actually correct.
Audit Event Syntax
Audit event syntax contains a readable, parseable version of Linux syscalls. This provides a comprehensive look into all local actions taken by your operating system.
To search an audit event, enter event_type = audit into the search field. You can use AND or OR operators to add key values to your search.
Notable key value pairs for audit events include:
Title (Type)
Key Value Pairs
Made Connection (type = connect)
src_addr, src_port, dst_port, ip, port, service, exe, user, group, PID, PPID, command, session
Accepted connection (type = accept)
src_addr, src_port, ip, port, exe, user, group, PID, PPID, command, session
Start (type = start)
exe, cwd, user, group, PID, PPID command, session, arguments
Bind Name to Socket (type = bind)
ip, port, exe, user, group, PID, PPID, command, session
Listen for socket connections (type = listen)
exe, user, group, PID, PPID, command, session
Load a kernel module (type = finit_module)
exe, user, group, PID, PPID, command, session
Get & set socket options (type = setsockopt)
exe, user, group, PID, PPID, command, session, tty
IP and Port fields are derived fields and are different for connect and accept events.
Title (Type)
Key Value Pairs
Threat Stack Use
Notes
Connect
IP and dst_port
The IP field is the destination ip of the connection. The port is the destination port (dst_port).
Accept
IP and dst_port
The IP field is the source IP of the remote connection. The port is the ephemeral (negotiated) return port for the tcp connection.
Network events are TCP connections only and do not include UDP connections.
CloudTrail Event Syntax
To search for a CloudTrail event, enter event_type = cloudtrail into the search field.
Due to the large number of CloudTrail events and key value pairs available and generated, Threat Stack does not index them all. This means, you cannot search every potential value pair. In rare cases, there could be information you want to search, filter, or suppress where you would need to contact us to implement.
Warning
CloudTrail is case sensitive for key value pairs. Examples include eventSource, eventName, user, and arnRole.
Using operators such as like, ends_with, or starts_with, automatically make queries lowercase within Threat Stack which causes the search to fail. This only pertains to event searches not to rule cloning and creation, rule filters, or suppressions.
Notable CloudTrail Keys
server
region
requestID
eventID
arnRole
accountId
timestamp
event_type
ip
eventName
eventSource
eventSourceType
Note
AWS does not provide a CloudTrail validation API endpoint. This means Threat Stack cannot distinguish between key value pairs that are not indexed or invalid key value pairs.
File Event Syntax
To search for a file integrity monitoring event, enter event_type = file into the search field.
Common search would be by filename, command, argument, or user.
Title (type)
Key Value Pairs
File (event_type = file)
filename, command, arguments, or user
Host Event Syntax
To search for host events, enter event_type = host into the search field.
Login sessions: open and close
Privilege escalations: successful and failed
Failed login sessions
Key Value Pairs
users
group
src_ip
Search by users, group (have to know exactly what you are looking for syntax wise authentication-success or authentication_failed or invalid_login otherwise the search will fail), or source IP (src_ip).
Note
Threat Stack differentiates between privilege escalation failed and a failed login session.
You can also search for the sigid. It can differentiate within privilege escalation.
Windows Event Syntax
To search for Windows events, enter event_type = winsec into the search field.
Key Value Pairs
exe
parent_name
command
dst_ip
src_ip
Login Event Syntax
To search for login events, enter event_type = login into the search field.
Common searches for login events include src_ip, "server" or src_host. Logout events are covered as Host events.
Key Value Pairs
src_host
agent
src_ip
Threat Intel Event Syntax
Threat Intel refers to Threat Intelligence. You can search for Threat Intel events using event_type = threatintel in the search field.
There are three important key value pairs: threatintel_source, threatintel_reason, and ip. You can determine what list it came from (source), what is the reputation (reason), and the location it came from (ip).
Key Value Pairs
user, command, arguments, port
threatintel_source, threatintel_reason, ip
Kubernetes Audit Event Syntax
To search for Kubernetes audit events, enter event_type = kubernetesAudit into the search field.
Key Value Pairs
action (Orchesttration action taken on cluster)
resource.type (Type of resource: pod, node, namespace)
Kubernetes Configuration Event Syntax
To search for Kubernetes configuration events, enter event_type = kubernetesConfig into the search field.
Key Value Pairs
namespace
role_name
role_type
verbs
View ArticleWhen creating a new rule, you have the option of selecting aggregations. The idea behind aggregation is to group alerts by a defined term. Aggregate fields define the uniqueness of the alert.
For example, if I built a host rule and set it to aggregate on "src_ip", and then run 11 commands from my local machine, I will see one alert in the Threat Stack Cloud Security Platform (CSP).
You can also define a time window for when the aggregation should occur. For additional information about alerts and aggregate fields, please review the Life Cycle of an Alert article.
Aggregate fields are available in the Threat Stack CSP for the following rule types:
Linux Host Rule
Aggregate Fields
exe
user
arguments
ip
port
command
session
src_ip
dst_ip
src_user
dst_user
filename
File Integrity Rule
Aggregate Fields
command
filename
user
exe
arguments
session
src_user
dst_user
CloudTrail Rule
Aggregate Fields
user
eventName
eventSource
ip
accountId
Threat Intelligence Rule
Aggregate Fields
threatintel_source
threatintel_reason
threatintel_type
ip
Windows Host Rule
Aggregate Fields
command
correlation
dns_host
dst_host
dst_ip
dst_ipv6
dst_port
exe
guid
sam_account
src_ip
src_ipv6
src_addr
src_port
user
sid
Kubernetes Audit Rule
Aggregate Fields
action
node_name
namespace
resource
name
type
Kubernetes Configuration Rule
Aggregate Fields
name
namespace
type
role_name
role_type
verbs
View ArticleOverview
The Threat Stack Cloud Security Platform (CSP) monitors your infrastructure for risky behavior and configurations. It provides real-time threat detection across your cloud workloads and alerts you of non-compliant changes to your infrastructure.
The Dashboard displays a comprehensive summary of your alerts, vulnerable servers, and monitored cloud profiles. The information provided enables you to take immediate action while ensuring your organizations compliance needs are met.
Select the image to enlarge it.
Note
Threat Stack supports cloud providers such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).
Accessing the Dashboard
You can access the Dashboard through your Threat Stack account.
Log into Threat Stack at https://app.threatstack.com.
In the Email field, type your account email address and click Next.
In the Password field, type your account password and click Next.
Note
If you do not remember your password, click the Forgot my password link. You will receive a password reset email containing instructions on how to reset your password.
Once you are successfully logged in, the Dashboard displays.
It is the default view in the Threat Stack CSP.
The Dashboard
The Dashboard contains the following panes:
New Alerts in the Last 24 Hours - Displays the number of Severity 1 and Severity 2 alerts that were triggered within the past 24 hours. Click View Alerts to view a list of all active alerts.
Vulnerable Servers - Displays the number of servers with high or medium rated vulnerabilities. Click View Servers to view a list of vulnerable servers.
Coverage Analysis - Displays a summary of the number of agents deployed, the number of AWS and non-AWS servers being monitored, along with any unmonitored EC2 instances.
Note
Agents deployed using Kubernetes and containers could affect the total number of Agents displayed in the Coverage Analysis pane.
Severity 1 Alerts Generated This Week - Displays a graph showing the number of Severity 1 alerts generated during the most recent week.
Severity 2 Alerts Generated This Week - Displays a graph showing the number of Severity 2 alerts generated during the most recent week.
Select the image to enlarge it.
For more information about alerts, please see the Alert Feature Overview article.
View ArticleAudit
CloudTrail
File Integrity Monitoring (FIM)
Kubernetes Audit
Kubernetes Configuration
Linux Host
Login
Threat Intelligence (ThreatIntel)
Windows Host
Related Articles
Introduction to Events
Overview: Events Feature
All Raw Events Tab
My Event Queue Tab
Search for Events
Supported Keys and Operators
View ArticleMost organizations receive thousands of events per day. You can search for events to quickly focus on the most important or relevant information you receive.
There are two ways to search for events in the Threat Stack CSP:
Keyword and operator search Use specific keywords and operators to find events that match your search criteria.
Date and Time picker Select specific dates and times within which to find events. By default, the Threat Stack CSP displays events that occurred during the previous six hours.
Keyword and Operator Search
You can search for specific events using keywords in the event metadata, such as user, timestamp, or session identification (ID). You can then use an operator to specify the specific keyword match, such as a username, a specific date and time, or a specific session ID number.
You can use keywords two ways:
Add metadata from an event to your search query
Type keywords into your search query
Add Event Metadata to Your Search Query
The Threat Stack CSP helps you quickly add event metadata to a search query. This allows you to find other events that occurred on the same server IP address or at the same date and time or by the same user, among other options.
Note
The Threat Stack CSP translates some metadata field names to other information in the search query. This is a result of the event normalization that occurs when events are ingested by the Threat Stack CSP. The following event metadata field names change in the search query:
server changes to agent_id (Audit, FIM, Linux Host, Login, ThreatIntel) or profile_id (CloudTrail)
PID changes to pid
PPID changes to ppid
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Find the event you want to use as the basis for your search.
Supported Keys and Operators
Next to the field you want to add to your search query, click the Expand button. The + Add to search menu displays.
Click + Add to search. The Threat Stack CSP adds the metadata to the search query field.
Repeat steps four and five for any other metadata you want to add to the search query. For more information on creating a usable search query, see Supported Keys and Operators.
Type Keywords into Your Search Query
The Threat Stack CSP matches search criteria to the following keys:
event_type
ip
type
cwd
pid
domain
arguments
port
timestamp
level
ppid
file_size
src_ip
dst_ip
protocol
user
command
exe
src_port
dst_port
agent
groud
sigid
filename
The Threat Stack CSP uses the following comparison operators:
=
!=
like
>
<
>=
<=
The Threat Stack CSP also uses the following logical operators:
and
or
&&
||
For more information, see Supported Keys and Operators.
Tip
If you need examples of keywords and operators, then click the Search icon to open the Search Language Tutorial dialog.
Date and Time Picker
The Date and Time picker allows you to select the start and end calendar dates, hours, and minutes within which to display events. By default, the previous six hours of events display. You cannot select a date and time later than the current date and time.
Tip
The Threat Stack CSP retains events for three calendar days.
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Click the Date and Time picker.
The Date and Time picker dialog displays.
On the calendar, click the date by which to start filtering. Available dates display in black font.
Click the date by which to stop filtering. If you only want to display events for one day, then click the same day twice.
To select the time, do one of the following:
To select a predetermined time window:
Click the Quick Jump link.
Several specific time frames display.
Click a time frame button.
Click the Apply button. The start and end times change to match the selection.
To use the Hour and Minute slider bars:
On the left calendar (start), click and drag the HR slider bar until the correct hour displays.
Click and drag the MIN slider bar until the correct minute displays.
On the right calendar (end), click and drag the HR slider bar until the correct hour displays.
Click and drag the MIN slider bar until the correct minute displays.
Click the Apply button. The start and end times change to match the selection.
Search Results
Search results display below your search criteria. By default, the Threat Stack CSP displays all events that occurred during the previous six hours.
There are three key components to search results:
Results Found The Results Found field displays the total number of events that match your search criteria.
Pages Pages display when more than 20 events match your search criteria. Click a page number button / First button / Previous button / Next button to go to a different page of search results.
Event Details Detailed metadata displays for each event that matches your search criteria. For more information, see All Raw Events Tab > Event Details.
Related Articles
Introduction to Events
Overview: Events Feature
All Raw Events Tab
My Event Queue Tab
View ArticleThe My Event Queue tab displays all events added to your queue using the Add to My Queue button. On the My Event Queue tab, you can search for and work with events in your queue.
Supported Keys and Operators
Tip
Users often add events that provide evidence of suspicious or malicious activity to their queue.
Events on the My Event Queue tab remain in your queue until you remove them from the queue. However, since the event is now in your queue, it can only be searched for in the My Event Queue tab it is no longer searchable in the All Raw Events tab.
Search for Events
You can search for specific events in the My Event Queue tab. For more information, see [hyperlink to Search for Events].
Event Details
Each event added to the queue includes metadata related to the action the event records. The event details displayed depend on the source of the event. For more information, see All Raw Events Tab > Event Details.
View an Event's JSON
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Click the My Event Queue tab. The My Event Queue tab displays.
Hover the mouse cursor over the event for which to view the JSON. The action bar displays.
Click the View JSON button. The Event JSON dialog opens.
Remove an Event from Queue
Remove events from your queue when they are no longer relevant to your workflow. If the event is still within the three day retention period, then it redisplays on the All Raw Events tab. If the event is outside of the three day retention period, then, if the event is not tied to an alert, it is removed from the Threat Stack CSP.
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Click the My Event Queue tab. The My Event Queue tab displays.
Hover the mouse cursor over the event to remove from the queue. The action bar displays.
Click the Remove Event button. The event no longer displays in the queue.
Related Articles
Introduction to Events
Overview: Events Feature
All Raw Events Tab
Search for Events
View ArticleThe All Raw Events tab displays every single event ingested by the Threat Stack CSP within the specified date range. On the All Raw Events tab, you can filter and work with events.
Note
The Threat Stack CSP retains events for three days. Events that trigger an alert are retained for 365 calendar days.
Search for Events
For more information, see [hyperlink to Search for Events].
Event Details
Each event ingested by the Threat Stack CSP includes metadata related to the action the event records. The event details displayed depend on the source of the event.
Supported Keys and Operators
Date and Time and Source Icon The date and time at which the event entered the Threat Stack CSP. The icon indicates the source of the event (Threat Stack Agent, CloudTrail, Kubernetes, or Windows).
Colored dot Indicates the source of an event. This is a quick way to visually distinguish events of particular importance to your workflow.
Metadata The data collected by the Threat Stack CSP about the event. The source of the event determines the data collected.
You can perform the following actions from an event:
Create a rule based on the event
View the JSON file for the event
Add events to the My Event Queue tab
Add event metadata to your search query
Create a Rule from an Event
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Hover the mouse cursor over the event from which to create a rule. The action bar displays.
Click the Create Rule button. The Add New [type of rule] Rule dialog opens.
Follow the instructions in the Rule Creation Overview article for the type of rule to create the new rule.
View an Event's JSON
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Hover the mouse cursor over the event for which to view the JSON. The action bar displays.
Click the View JSON button. The Event JSON dialog opens.
Add Event to My Event Queue Tab
Click the Add to My Queue button to add an event to the My Event Queue tab. For more information, see My Event Queue.
Log into the Threat Stack CSP.
Click the Events tab. The Events screen displays.
Hover the mouse cursor over the event to add to the My Event Queue tab. The action bar displays.
Click the Add to My Queue button. A message displays in the lower right corner of the screen informing you that the event has been added to the My Event Queue tab. From now on, you can only search for the event in the My Event Queue tab.
Related Articles
Introduction to Events
Overview: Events Feature
My Event Queue Tab
Search for Events
View ArticleA vast amount of events occur in your infrastructure every single second. The Threat Stack Cloud Security Platform (CSP) helps you view, organize, and find events of interest to your security concerns within this array of information.
To assist you in this work, the Events tab contains the following information:
All Raw Events tab Displays every single event ingested by the Threat Stack CSP within the specified date range. For more information, see All Raw Events Tab.
Note
The Threat Stack CSP retains events for three days. Events that trigger an alert are retained for 365 calendar days.
My Event Queue tab Displays any event you select for further review. For more information, see [hyperlink to My Event Queue].
Search for Events A variety of criteria you can use to search for and display selected events. For more information, see [hyperlink to Search for Events].
Supported Keys and Operators
What Events Does the Threat Stack CSP Ingest?
Audit
CloudTrail
File Integrity Monitoring (FIM)
Kubernetes Audit
Kubernetes Configuration
Linux Host
Login
Threat Intelligence (ThreatIntel)
Windows Host
Related Articles
Introduction to Events
All Raw Events Tab
My Event Queue Tab
Search for Events
View ArticleEvents are the backbone of your cybersecurity operation. Events record everything taking place in your infrastructure. The Threat Stack Cloud Security Platform (CSP) ingests events and assists you in creating a baseline normal, everyday activity. If an event deviates from the baseline, then a Rule triggers an Alert to tell you about potentially malicious activity. Events, therefore, are critical to protecting your infrastructure.
What Is an Event?
Events are individual actions that take place within your infrastructure. Events contain metadata related to the action, such as an event identification (ID), the date and time the event took place, and the action taken for example, command or exe. See Overview: Events Feature for a specific list of the types of events the Threat Stack CSP ingests.
You apply rules to events as they enter your Threat Stack CSP. If the metadata in the event matches an applied rule, then an Alert triggers. Threat Stack ties the event to the alert, which makes it easier to identify the source of potentially anomalous behavior in your infrastructure.
Where Do I Find Events in the Threat Stack Application?
Events display on the Events tab in the Threat Stack CSP.
Supported Keys and Operators
Why Do I See Events in My Threat Stack CSP?
The events you see in your Threat Stack CSP record actions taking place in your infrastructure. Events are stored for three calendar days. Events tied to alerts are stored for one calendar year.
Related Articles
Overview: Events Feature
All Raw Events Tab
My Event Queue Tab
Search for Events
View ArticleTo clone an existing rule:
Log into the Threat Stack Cloud Security Platform (CSP).
Click the Rules tab.
In the ruleset from which to clone the rule, click the +New Rule button.
Select Clone Existing Ruleand click Next: Details.
Do one of the following:
Use the search bar to find the rule you want to clone.
Select the check box next to the name of a rule from the list of rules.
Once you have selected all the rules you want to copy, click the Clone Rule button.
Note
Suppressions will be cloned with the rule you select.
View ArticleThreat Stack's Threat Intelligence rule types will alert you to suspicious connections using a curated list of IP addresses from various sources. Threat Stack monitors your environment with the Agent installed, alerting you to problem package installs. For additional information about Threat Stack's Threat Intelligence feature, please review the Threat Intelligence Feature Overview article.
You can create a Threat Intelligence rule in the Threat Stack Cloud Security Platform (CSP).
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Automatically Integrate with AWS using CloudFormation
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Threat Intelligence Rule Set.
The Add Host Rule dialog displays.
Select Threat Intelligence Rule from the list and click Next: Details to proceed.
The Add Threat Intelligence Rule dialog displays. You will be able to specify the rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.
After making your selection, click Next: Filter.
The Threat Intelligence Rule Filter pane displays.
Tip
If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.
However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.
After specifying a rule filter, click Create Rule.
The rule creates and displays on the Rules page.
View ArticleA file integrity rule will alert you to changes to critical files on your system. You can configure File Integrity Monitoring (FIM) in the Threat Stack Cloud Security Platform (CSP). For additional information about FIM, please review the Overview of File Integrity Monitoring article.
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Automatically Integrate with AWS using CloudFormation
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.
The Add Host Rule dialog displays.
Select File Integrity Rule from the list and click Next: Details to proceed.
The Add File Rule dialog displays. You will be able to specify the file rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.
After making your selection, click Next: File Paths.
The File Rule Paths pane displays. You can specify file paths to monitor.
Note
Enabling recursive monitoring for a specific file path allows Threat Stack to monitor changes in that directory andall of its subdirectories.
Tip
If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.
However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.
After specifying a file path and FIM events to monitor, click Create Rule.
The rule creates and displays on the Rules page.
View Article
Threat Stack collects raw event data from the Agents installed on your machines and delivers it to the Threat Stack Cloud Security Platform (CSP) to be processed. Threat Stack uses the rules you create to initiate alerts based on the information you want reported. Your defined suppressions determine whether you are notified about behavior you consider normal.
Rulesets can be considered buckets, inside of which rules are built. Suppressions are then associated with the rule directly. In most cases, a server must be associated with a ruleset bucket in order for an alert to be initiated by a rule (This currently excludes CloudTrail rules which rely on tags).
The following rule types can be configured in the Threat Stack CSP.
Creating a Kubernetes Configuration Rule
Host Rule (Linux or Windows)
Host rules monitor events generated from general activity in the Operating System (OS). Examples include kernel activity, network activity, and user activity. For additional information about configuring a host rule, please review the following articles:
Creating a Linux Host Rule
Creating a Windows Host Rule
File Integrity Rule
File rules are for monitoring file changes and integrity of the files themselves. In addition to creating the rule, you need to define the path and the events to monitor.
Examples include file opens, file deletes, configuration file changes, and system file changes. For additional information about configuring a file integrity rule, please review the Creating a File Integrity Rule article.
CloudTrail Rule
A CloudTrail rule is a rule built specifically to monitor your connected Amazon Web Services (AWS) CloudTrail service.
Examples of CloudTrail rules include IAM policy changes, too many API calls, and access denied. For additional information about configuring a CloudTrail rule, please review the Get Started with CloudTrail Alerting article.
Threat Intelligence Rule
Threat Stack provides a database of known threats and helps you reference them to keep you safe.
Examples of Threat Intelligence rules are inbound or outbound IP connections, or system vulnerabilities unveiled after an Agent scan. For additional information about configuring a threat intelligence rule, please review the Creating Threat Intelligence Rule Types article.
Clone Existing Rule
This is an opportunity to clone current rules and alter them, or update them to catch new events. For additional information, please review the Clone Existing Rule article.
Kubernetes Audit Rule
Kubernetes Audit rules monitor events generated from orchestration activity related to node/pod/container actions, such as creations and modifications. For additional information about configuring a Kubernetes Audit rule, please review the Creating a Kubernetes Audit Rule article.
Kubernetes Configuration Rule
Kubernetes Config rules monitor role, role bindings, and cluster role bindings events generated periodically. For additional information about configuring a Kubernetes Configuration rule, please review the article.
View ArticleA Host rule will alert you to user activity on your system. You can add a host rule in the Threat Stack Cloud Security Platform (CSP).
Note
If you are looking to update a ruleset, please review the Updating a Ruleset article.
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Automatically Integrate with AWS using CloudFormation
The Add Host Rule dialog displays.
Select Host Rule from the list and click Next: Details to proceed.
The Add Host Rule dialog displays. You will be able to specify the rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.
After making your selection, click Next: Filter.
The Host Rule Filter pane displays.
Tip
If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.
However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.
After specifying a rule filter, click Create Rule.
The rule creates and it displays on the Rules page.
View Article
You can create a File Integrity Monitoring (FIM) rule with a specific user suppression to monitor changes in certain folders by unauthorized users. To do so, perform the following actions:
Create a rule to monitor changes in all home directories
Create suppressions for each user for their own home directory
Create a FIM Rule to Monitor a Folder
You can create a File Integrity Rule to monitor changes to a folder.
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
How do I Suppress an Alert?
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.
The Add Host Rule dialog displays.
Select File Integrity Rule from the list and click Next: Details to proceed.
The Add File Rule dialog displays. You will be able to specify the file rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the Life Cycle of an Alert article.
Complete the fields for Rule Name, Alert Title and Alert Description. Click the Aggregate Fields to display the drop-down menu. Select User from the list.
After making your selection, click Next: File Paths.
The File Rule Paths pane displays. You can specify file paths to monitor
Specify a File Integrity Path and select the checkbox for Recursive monitoring.
Note
Enabling recursive monitoring for a specific file path allows Threat Stack to monitor changes in that directory and all of its subdirectories.
Click the Events To Monitor field to display the drop-down menu. Select ALL from the list.
Tip
If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.
However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
After specifying a file path and FIM events to monitor, click Create Rule.
The rule creates and it displays on the Rules page.
Add a User Specific Suppression to a FIM Rule
Follow these instructions to remove monitoring for users in their own home directory.
Within the Rules tab, click the Suppressions link to display the Suppressions pane.
Click the + New Suppression button.
The suppression text field is displayed.
After specifying your suppression filter options, click the Add New Suppression button.
The suppression saves to the rule.
Related Articles
Creating a File Integrity Rule
View ArticleOverview
This article reviews the life cycle of an alert to help you better understand how to perform the following actions:
Create a rule
Maximize the effectiveness of that rule
Review an alert
Resolve an alert
Use Case
You want to create a rule that shows a Severity 2 alert when 5 'sudo' commands happen in an hour. This rule has Threat Stack generate an alert anytime a user escalates their privileges on the monitored host using the `sudo` command.
The alert life cycle starts when you create a rule on the Threat Stack Rules page.
1. Create a Rule
Every rule must include the following components:
Rule Name: It indicates the name of the ruleset.
Alert Title: It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. See Rule Aggregation for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.
Rule Filter : It indicates the criteria the filter is using to decide if an alert should display.
Severity: There are three levels of behaviors to indicate the severity of the alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Note
You should select the aggregation fields that match the substitution fields in the alert title (For example, if you want to substitute "exe" and "user" dynamically with the "user" and "executable", you should select user and exe as the aggregation fields).
Example of Rule Creation
The example below walks you through the process of cloning and modifying an existing "Privilege Escalations" rule in the Base Ruleset. You can clone an existing rule by navigating to the Rules page.
Click the + New Rule button.
How do I Suppress an Alert?
The Add Host Rule dialog displays.
Select Clone Existing Rule and click the Next: Details button.
In the Select existing rules to clone field, search and select the existing Privilege Escalations rule.
After making your selection, click the Clone 1 Rule button.
The cloned rule will be displayed in the rules list.
You can confirm the Severity of alerts associated with the rule. If necessary, change the severity level by clicking the severity button for your desired alert level.
In the right view pane, the Details screen displays. You can make changes to the following:
Rule Name
Alert Title
Alert Description
Aggregate Fileds
Frequency of alert
Note
In the Aggregate Fields, confirm you have the correct aggregations selected.
In this example, the following updates were made:
The Rule Name field was updated to Sudo five in an hour {{exe}} by {{user}} with arguments {{arguments}}.
The Alert Title field was updated to User Activity (Sudo five in an hour) {{exe}} ran by user {{user}} with {{arguments}}.
The Alert Description field was updated to This alert tracks all sudo ran by a non-root user and alerts you if users run 5 sudo commands in an hour.
The alert frequency field was updated to 5 times, and the time window for the alert was updated to 1 hour.
Click the Update Rule button to save your changes.
Navigate to the Rule Filter pane.
In the Filter field enter the following filter criteria: command = "sudo" and type ="start".
Click the Update Rule Filter button .
You have successfully created a new rule.
2. Maximize the Effectiveness of the Rule
When you create a rule, you have the option to select aggregations, alert thresholds, and a time window.
Aggregation Field
Aggregate fields define the uniqueness of the alert.
In our example for rule creation, we selected "execute" and "arguments" as aggregations. Hence, if a user executes the same command within the same argument more than once, Threat Stack considers it an identical event and updates the original alert within the alert threshold.
Within the context of aggregation, if a user performs the same execution but enters a different argument, a new unique alert displays since Threat Stack considers it a different alert.
Alert Thresholds
The alert threshold counts the number of times an event matches the defined filter and aggregations. It displays an alert only after the count matches the alert criteria.
In our example, we had you set the alert threshold as "5 events in a 1 hour period". This means, if a user executes the same argument 5 times within an hour then Threat Stack generates only 1 alert.
Time Window
The time window is the span of time specified to generate an alert based on the number of times an event was executed.
In our example, if the same alert generates more than once within a time window, Threat Stack would update the existing alert instead of generating a new alert. When Threat Stack updates an existing alert, it attaches the event to the alert record for you to review.
You can learn more about alerts in the Threat Stack Dashboard in the "Review an Alert" section below.
3. Review an Alert
At this point you have created a rule and specified the criteria for an alert. We can now review what an alert looks like on the Alerts page if an event triggers it.
The Alerts Page
As a reminder, the Alerts page contains:
Organized view (default and customizable tabs)
By default, Threat Stack sorts alerts by severity, type, active, or dismissed.
Search field
Alert trends over time (histogram)
Alert information table and filter rule and ruleset details
Reviewing Alerts
We recommend using the Alert Trends histogram to navigate to alert spikes. This can help you access alert details quickly and efficiently review additional information.
In the Alert Trends, you can select a desired time frame along the histogram to view the behaviors that caused the alerts. As you move the vertical markers to your desired timeline, the information in the right view pane, such as "Filter by Rule" and "Filter by Tags", changes to display relevant content related to the behaviors in the body of the alerts. The filter pane also shows the specific behaviors and events to help you determine whether any further analysis and action is required.
Alert Details Information
When reviewing alerts in list view, the following information is displayed:
Severity level of the alert
Title of the alert
Date and time of the alert
Alert suppression icon
Select an alert to view detailed event information.
Additional information about the events contributing to the alert are displayed, such as:
The date and time of the first event that triggered the alert (The default timestamp).
The timestamp of the last event that contributed to the alert.
The last five contributing events related to the alert.
Clicking the View Contributing Events link displays the last five contributing events in chronological order starting with the most recent event.
4. Resolve an Alert
On the Alerts page, you can view, suppress, and dismiss alerts. The "Dismiss Alert" functionality enables you to acknowledge particular behaviors and track the dismissed alerts for compliance.
Dismissing an Alert vs Suppressing an Alert
When you dismiss an alert, it removes it from view. If the behavior happens again the alert will re-appear.
Suppressing an alert whitelists the behavior. Hence, you will not see the alert again. If you suppress an alert, it indicates youdon'twant to receive alerts about the behavior. See the article for more information.
Dismissing an Alert
Dismissing an alert indicates you have reviewed and acknowledged a particular behavior, or a set of behaviors. From a compliance perspective, a record of dismissed alerts shows an auditor you reviewed and acknowledged particular behaviors.
Note
Youdon'tdismiss at the alert level. You dismiss alerts at the rule level.
To dismiss an alert or multiple alerts, navigate to the Alerts page.
On the Alert Trends histogram, navigate to an alert spike using the vertical markers.
After selecting an alert timeline, review the Filter by Rule pane for the rule filter that triggered the alert behavior.
Select a specific alertto review the contributing events and determine why the behavior happened.
Select the checkbox for the alert. The Dismiss pane displays in the right view.
Select your Dismiss Alerts Reason and click the Dismiss [#] Alert button.
You can review dismissed alerts in the Dismissed Alerts tab.
View ArticleA Windows host rule will alert you to user activity on your Windows system. You can add a host rule in the Threat Stack Cloud Security Platform (CSP).
Note
If you are looking to create a Linux host rule, please review the Creating a Linux Host Rule article.
Navigate to the Rules tab and select a ruleset from the list.
Click the + New Rule button.
Automatically Integrate with AWS using CloudFormation
Note
You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.
The Add Host Rule dialog displays.
Select Windows Host Rule from the list and click Next: Details to proceed.
The Add Windows Host Rule dialog displays. You will be able to specify the rule details.
Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.
Severity 1 alerts are the highest elevation of behaviors.
Severity 2 alerts are the second highest elevation of behaviors.
Severity 3 alerts are the third highest elevation of behaviors.
Rule Name (Required): It indicates the name of the ruleset.
Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.
Alert Description: It indicates a brief summary of the alert.
Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.
Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.
After making your selection, click Next: Filter.
The Windows Host Rule Filter pane displays.
Tip
If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.
However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.
After specifying a rule filter, click Create Rule.
The rule creates and displays on the Rules page.
View Article
Amazon Web Services (AWS) allows users to assign tags to their AWS resources. Tags are simple labels that consist of a customer-defined key and value. Examples include role:webserver or env:production.
Once you integrate Threat Stack and AWS, the Threat Stack Cloud Security Platform automatically ingests EC2 tag information. You can then use tags to apply specific rules to servers. This simplifies and speeds up tuning and deployment, and improves relevancy of alerts.
Prerequisites
Access to the Threat Stack console.
An enabled Threat Stack AWS EC2 Agent correlation. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
View AWS EC2 Tags
Note
AWS EC2 tags are not available for CloudTrail or Configuration Audit rules.
To see which tags are applied to a rule, in the Create Rule or Edit Rule dialog, click the Deployment interface.
Tip
If you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
View tags from rules:
FAQ: Do I have to use AWS EC2 tags?
View tags from alerts:
Add AWS EC2 Tags
Note
AWS EC2 tags are not available for CloudTrail or Configuration Audit rules.
Add AWS EC2 tags when you create a rule
Log into Threat Stack.
Click Rules. In the right view pane, the Rules page displays.
Click the Rule Set to which to add the rule.
Click the + New Rule button. In the right display pane the + Add Rule page displays.
Do one of the following:
Select a type for your new rule (Host Rule, File Integrity Rule, CloudTrail Rule, Threat Intelligence Rule orWindows Host Rule).
Click the Next: Details button. The Add [Rule Type] Rule page displays.
In the Rule Name (required) field, type the name of the rule. Threat Stack recommends using the rules purpose as a title.
In the Alert Title (required) field, type the title of alerts tied to this rule. Threat Stack recommends using the rule name as the alert title.
Click the Next: Filter button. The + Add Rule page displays the 3. [Rule Type] Filter Rule page.
In the Apply the new rule to events that match this filter field, type the criteria by which the rule singles out events for further inspection by Threat Stack.
Click the Next: Deployment button. The + Add Rule page displays the 4. Deployment Options page.
Tip
If you do not see the Deployment tab, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
Click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.
Tip
This field is pre-populated with all tags available on your AWS resources.
Click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu select one or more AWS EC2 tags to ignore when applying the rule.
Tip
This field is pre-populated with all tags available on your AWS resources.
Click the Apply Tags button.
The rule creates and the tag(s) apply to the rule. Within 10 minutes Threat Stack will process the rule and the tag(s), and apply the rule to any of your AWS hosts with a matching tag.
Clone an existing rule.
Select the Clone Existing Rule type button.
Click the Next: Details button. The Clone Existing Rules page displays.
Select the existing rule(s) to clone.
Click the Clone [no.] Rule button. The new rule creates. In the right view pane, the rule details display.
In the Deployment section of the rule, click in the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.
Tip
If you do not see the Deployment section, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
This field is pre-populated with all tags available on your AWS resources.
Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.
Click the Apply Tags button.
The rule creates and the tag(s) apply to the rule. Within 10 minutes Threat Stack will process the rule and the tag(s), and apply the rule to any of your AWS hosts with a matching tag.
Add AWS EC2 tags to an existing rule
Log into Threat Stack.
Click Rules. In the right view pane, the Rules page displays.
Select the rule to which to apply AWS EC2 tags. In the right view pane, the rule displays.
In the Deployment section, click the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.
Tip
If you do not see the Deployment section, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
This field is pre-populated with all tags available on your AWS resources.
Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.
Click the Apply Tags button.
The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.
Add AWS EC2 tags to a rule from an alert
Log into Threat Stack.
Click Alerts. In the right view pane, alerts display.
Select an alert for the rule to which you want to apply an AWS EC2 tag.
Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.
Click the Deployment tab. The Deployment page displays.
Tip
If you do not see the Deployment tab, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.
Click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.
Tip
This field is pre-populated with all tags available on your AWS resources.
Optionally, click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu, select one or more AWS EC2 tags to ignore when applying this rule.
Click the Apply Tags button.
The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.
Edit AWS EC2 Tags
You can change the AWS EC2 tags applied to rules at any time.
Edit AWS EC2 tags applied to a rule
Log into Threat Stack.
Click Rules. In the right view pane, the Rules page displays.
Select the rule to which to edit AWS EC2 tag(s). In the right view pane, the rule displays.
In the Deployment section, click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.
Tip
This field is pre-populated with all tags available on your AWS resources.
Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.
Click the Apply Tags button.
The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.
Edit AWS EC2 tags applied to a rule from an alert
Log into Threat Stack.
Click Alerts. In the right view pane, alerts display.
Select an alert for the rule to which you want to edit AWS EC2 tag(s).
Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.
Click the Deployment tab. The Deployment page displays.
Click the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.
Tip
This field is pre-populated with all tags available on your AWS resources.
Optionally, click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu, select one or more AWS EC2 tags to ignore when applying this rule.
Click the Apply Tags button.
The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.
Delete AWS EC2 Tags
You can delete an AWS EC2 tag associated with a rule at any time.
Note
You cannot remove a tag from your AWS resources by deleting it from a rule in Threat Stack.
Delete AWS EC2 tags applied to a rule
Log into Threat Stack.
Click Rules. In the right view pane, the Rules page displays.
Select the rule from which to delete AWS EC2 tag(s). In the right view pane, the rule displays.
In the Deployment section, in the Applied tags field, click the X button next to the tag(s) to delete.
The tags delete from the rule.
Optionally, in the Exclude all hosts with any of the following tags from this rule field, click the X button next to the tag(s) to delete. The tags delete from the rule.
Click the Apply Tags button. The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.
Delete AWS EC2 tags applied to a rule from an alert
Log into Threat Stack.
Click Alerts. In the right view pane, alerts display.
Select an alert for the rule from which you want to delete AWS EC2 tag(s).
Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.
Click the Deployment tab. The Deployment page displays.
In the Applied tags field, click the X button next to the tag(s) to delete. The tags delete from the rule.
Optionally, in the Exclude all hosts with any of the following tags from this rule field, click the X button next to the tag(s) to delete. The tags delete from the rule.
Click the Apply Tags button. The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.
Related FAQs
FAQ: How are AWS EC2 tags ingested by Threat Stack?
FAQ: How does Threat Stack apply AWS EC2 tags?
FAQ: How long does it take for new / edited / deleted AWS EC2 tags to show up?
FAQ:Whydon'tAWS EC2 tags to show up for CloudTrail?
FAQ: Whydon'tAWS EC2 tags show up for Configuration Audit?
View ArticleOrganizing, viewing and curating alerts is a vital piece of the workflow in managing security of cloud environments. Based on customer feedback and for an improved overall experience, we re-designed the Alerts page to address the following issues:
Significantly faster page loading, even with thousands of open alerts.
Quickly search through alerts - for example, show me all alerts that have a particular user name or ones with a specific command or argument(s).
Create customized alert views - for example, every time I log into my account I want to see alerts from my database servers.
Note
The default view of the Alert Trends histogram is now seven days. Double-clicking the histogram will revert to displaying a date range covering one year.
How do I Suppress an Alert?
Important
If a rule that triggered an alert is deleted, a generic icon () displays on the Alerts page instead of the icon associated with the triggered rule.
Features
Tabs as focus areas: We narrowed in on the well-known concept of browser tabs as focus areas, with in-built default tabs and the ability for customers to create and save their own tabs. Each tab can be customized to match the originating rulesets and/or originating servers (EC2 tags).
Live alert loading: The Alerts page will display alerts as they come in. It will not delay the loading of alerts coming into the Threat Stack Cloud Security Platform (CSP).
Search on alert titles: All tabs have a "Filter by Title" search field. Results appear as the users type in the words in the search bar.
Alert Tabs
The following alert tabs are displayed on the Alerts page:
Sev 1: It displays a histogram and a list for the highest level of alerts.
Sev 2: It displays a histogram and a list for the second highest level of alerts.
Sev 3: It displays a histogram and a list for the third highest level of alerts.
CloudTrail: It displays a histogram and a list of alerts related to CloudTrail events in your Amazon Web Services (AWS) environment. For more information, please review the Get Started with CloudTrail Alerting article.
Note
To view CloudTrail alerts, ensure you have enabled integration of your AWS environment within the Threat Stack CSP. For more information, please review the AWS Integrations Overview article.
All Active Alerts: It displays a histogram and a list of all active alerts.
Dismissed Alerts: It display a histogram and a list of dismissed alerts.
When you dismiss an alert, it removes it from view. If the behavior happens again the alert will re-appear.
Adding a New Alert Tab
You can customize the Alerts page by adding a new tab.
Click the Add New Tab button
The + Add New Tab dialog displays.
After specifying a tab name and description, click the Add New Tab button.
The newly added tab displays with its name and description.
Viewing a Hidden Alert Tab
You can display hidden tabs on the Alert page.
Click the Hidden Tabs button.
The Select a Tab dialog displays.
Search or select the tab name to display. In this example, DismissedAlerts was selected.
The tab is now visible on the Alerts page. To revert to hiding the tab, click the closeicon (x) to remove it.
Alert Filtering Options
You can filter your alerts for troubleshooting or investigative purposes. There are various filter categories to choose from on the Alerts page.
Select an alert tab.
Click the expand / collapse button to display the filter dialog.
Some of the filter options are as follows:
Filter by Rule
Filter by Tags
Filter by Ruleset
Filter By Severity
Note
This filter option does not appear for Severity 1 (Sev 1), Severity 2 (Sev 2) and Severity 3 (Sev 3) alerts.
After making your selection, your filtered alerts are displayed.
Note
You can select multiple filter options from different categories. For example, you can select a rule from the Filter by Rule pane and a ruleset from the Filter by Ruleset pane.
To remove your newly added filters, click the Clear all filters button.
Related Articles
Alert Feature Overview
Alert Trends Functionality
Life Cycle of an Alert
View ArticleOverview
Threat Stack designed the Alert Trends histogram feature to help you understand trends of abnormal behaviors. This feature can help you accelerate the time it takes to manage alerts inside of Threat Stack.
How do I Suppress an Alert?
Important
The default view of the Alert Trends histogram is seven days. Double click the histogram to display a date range covering one year.
The Feature
The Alerts page shows the Alert Trends histogram organized over time by the number and severity of alerts found on a daily basis. This can help you better track the abnormal spikes of alerts and review the behaviors that caused the events.
In the Alert Trends histogram, you can select a desired time frame along the histogram to view the behaviors that caused the alerts. As you move the vertical markers to your desired timeline, the information in the right view pane, such as "Filter by Rule" and "Filter by Tags", changes to display relevant content related to the behaviors in the body of the alerts. The filter pane also shows the specific behaviors and events to help you determine whether any further analysis and action is required.
Daily Use and Workflow
This section reviews the optimal workflow to help you manage (review, acknowledge, dismiss, or suppress) your alerts quickly using the Alert Trends view and the Alerts filter.
Use Case: Review and Dismiss an Alert
In this scenario, you log into Threat Stack and navigate to the Alerts page. Click List View to display the latest alerts in chronological order, with the most recent alerts appearing first.
You review the Alert Trends histogram to confirm the following:
The date with the most alerts
The trend that caused the alerts since your last login
Important
Requests to dismiss alerts are queued and do not occur in real time. Hence, refreshing the Alerts page immediately after dismissing an alert can cause the page to incorrectly display the alert count.
In this example, the largest set of alerts was generated between August 15th and August 19th.
Move the vertical markers along the histogram to the date range with the most number of alerts.
All alerts generated during that timeframe are displayed. Ensure List View is selected for a detailed list of the alerts.
Review the Filter by Rule pane to determine the rule filter that caught the alert behavior.
In this example, some of the rule filters were:
CloudTrail Activity (Access Denied) for {{eventName}} by {{user}}
CloudTrail: KMS Read Event: {{user}} {{eventName}} in account {{accountId}}
Select a specific alert to review the contributing events and determine why the behavior happened.
You can select the alerts associated with the behavior and then:
Acknowledge and dismiss the behavior (see the Life Cycle of an Alert article for resolving an alert)
Suppress the behavior (see the How do I Suppress an Alert? article)
For this example, we dismiss the alert by clicking the Dismiss 1 Alert button.
Repeat this process as necessary. We recommend reviewing other alert behavior spikes and use the dismiss or suppress functionality as needed.
Additional Alert articles include:
Alert Feature Overview
Life Cycle of an Alert
View ArticleIntroduction
Threat Stack is a behavior based anomaly detection platform, based on telemetry delivered into the platform from various sources, including your host and your infrastructure.
What is an Alert?
Alerts are behavior anomalies elevated from the stream of raw telemetry by rule filters. Alerts contain two main components:
The alert title
The contributing events
Term
Definition
Contributing Events
The raw telemetry that caused the anomaly to happen.
Alert Title
The name and substitutions (dynamic content) that adds context to the alert.
The substitution fields should match the aggregation fields selected for the alert. The aggregation fields define the uniqueness of the alerts. See the Life Cycle of an Alert article for additional information on aggregations.
Alert Trends Functionality
Where Do I Find Alerts in the Threat Stack Application?
In the left navigation bar, select the Alerts tab. The Alerts page displays the following information:
Alert Trends over time in the form of a histogram
Alerts sorted by severity, type, active or dismissed
Alert information table including filter rule and ruleset details
On the Alerts page you have the option to:
Select an alert to review its alert details
Suppress an alert
Dismiss an alert (if you dismiss an alert it displays in the Dismissed Alerts tab)
Important
If a rule that triggered an alert is deleted, a generic icon () displays on the Alerts page instead of the icon associated with the triggered rule.
Why Would an Alert Trigger?
Alerts trigger when Threat Stack detects a behavior anomaly deemed inappropriate based on the rules you enabled or created. Rules require a filter to match behaviors against raw telemetry.
Term
Definition
Telemetry
Events and behavior anomalies.
Rules
Behaviors that you want to catch from the raw telemetry stream.
Rule Filter Example
Behavior to Catch
Rule Filter
Privilege escalations
command =sudo
User access
Event_type =login"
If a rule displays alerts for behavior you consider baseline or normal, you can create a suppression filter to have it no longer report that behavior. The content should match the aggregation fields selected for the alert. The aggregation fields define the uniqueness of the alerts. See the How do I Suppress an Alert? article.
Threat Stack includes three levels of elevation of behaviors to indicate the severity of the alert:
Severity 1 (Sev 1): It is the highest elevation of behaviors.
Recommended for behaviors and scenarios that should wake you up in the middle of the night. Only used for behavior anomalies where an action and remediation runbook exists.
Severity 2 (Sev 2): It is the second highest elevation of behaviors.
Recommended for behaviors you want to monitor and review with stakeholders to improve over time.
Severity 3 (Sev 3): It is the third highest elevation of behaviors. Sev 3 alerts are automatically dismissed after 30 days.
Recommended for behaviors that companies log for compliance or forensics purposes.
Additional Alert articles include:
Life Cycle of an Alert
How do I Suppress an Alert?
View ArticleThreat Stack provides a secure integration with your Amazon Web Services (AWS) account to monitor changes to your infrastructure through CloudTrail. For more information about setting up a CloudTail integration, please review the AWS Integrations Overview article.
This article covers the following:
CloudTrail rules best practices and examples
CloudTrail alerts
What is Threat Stack CloudTrail Monitoring?
AWS CloudTrail monitoring is one way Threat Stack comprehensively monitors your infrastructure and workload. Using Threat Stacks CloudTrail integration, you can be alerted on changes to your instances, security groups, S3 buckets, and access keys. You can also determine whether any of these changes had adverse effects on your systems.
If you have multiple AWS accounts, you can see across accounts to track risk in the Threat Stack Cloud Security Platform (CSP). With CloudTrail monitoring enabled, you can reduce the exposure window of an attack or an insider threat.
How does Threat Stack Alert on Non-Compliant Changes to Your Infrastructure?
Threat Stack has built-in rules (part of the CloudTrail Base Rule Set) that capture several AWS best practices, alerting users when non-compliant calls are made to their infrastructure.
Let's review some examples below.
Example 1: AWS account was compromised with the attacker compromising logs
When an account is compromised, one of the first things the attackers would do is to stop logging the call and delete existing trails. The Cloud Trail Admin Activity ruleset monitors administrator activity, including updates to trails and creation of new trails.
How do I Suppress an Alert?
This rule was created with the "eventName" as the parameter for the rule filter. You can create any rule based on any "eventName" or "eventSource".
Example 2: Users running instances in non-standard hidden regions incurring costs
The ruleset in this example monitors and alerts you when an instance is launched into a non-standard region.
This rule was created with the "eventName" and region combination as parameters for the rule filter.
Example 3: Are security groups getting created or changed outside of your security policy?
The ruleset in this example monitors and alerts you when a security group is changed.
This rule was created with the following "eventName" parameter keys:
AuthorizeSecurityGroupEgress
AuthorizeSecurityGroupIngress
CloudTrail Alerts
CloudTrail alerts appear on the Alerts page.
Clicking the CloudTrail tab will display a histogram and a list of all active CloudTrail alerts.
Clicking the expand / collapse button will display the Filter dialog. For additional information about alert filtering options, please review the Alert View article.
Clicking List View will display alerts by severity level.
Select the image to enlarge it.
Clicking an alert will display the alert preview pane along with the following information:
The date and time of the API call
The user name that made the API call
The account associated with the API call
Clicking the View Contributing Events link displays the last five contributing events that caused the alert.
In this example, there was only one contributing event.
Clicking the View/Edit Rule link displays an Edit CloudTrail Rule dialog, enabling you to view and update the following fields:
The rule name
The alert title
Filter options
Suppression settings
You can choose to not get alerts on specific users or actions by adding a suppression. For additional information on suppressing alerts, please review article.
View ArticleThis document can answer some frequently asked questions (FAQs) about the Threat Stack CloudTrail Monitoring feature. It can also provide some basic troubleshooting suggestions.
Important
Access to CloudTrail information will vary based on the Threat Stack Plan you purchased.
Frequently Asked Questions
How do I know if CloudTrail Monitoring works?
When Threat Stack connects properly with CloudTrail, you can view events and alert details on either the Alerts or Events page.
The example below shows a view of CloudTrail alerts.
Alternatively, you can view CloudTrail events on the Events page by entering event_type = cloudtrail into the search field.
Select the image to enlarge it.
What if I don't see CloudTrail alert details on the Alerts page?
If you don't see an alert, wait 10 minutes. If no alerts display after 10 minutes, you can test CloudTrail alerts by triggering an event. Event example: Log in to the console.
If the event you trigger displays in CloudTrail but not in the Threat Stack Cloud Security Platform (CSP), please see the troubleshooting suggestions below.
What does the clock icon (Status column on the Settings page in the CSP) mean?
The clock ( CloudFormation template ) icon indicates Threat Stack's attempt to connect to Amazon Web Services (AWS). This connection can take upwards of 10 minutes. Navigate away from the Settings page and return after 10 minutes. You will see a green checkmark () icon or an error () icon indicating the success or failure of the connection attempt.
What if I see a green checkmark () icon but I don't see CloudTrail events or alert details?
If you experience this issue, it indicates Threat Stack can connect to your AWS account but cannot display data.
Important
Your feature plan will determine whether CloudTrail alert details are displayed on the Alerts page.
Please review the following troubleshooting suggestions and best practices:
Ensure no other application can read messages off this queue.
If another application can acknowledge messages off the same queue, it will interfere with Threat Stack's ability to read the messages.
Confirm the message ticker indicates 1 messages in the SQS Queue.
Navigate to the SQS service in the AWS Console.
Choose the appropriate queue.
Review the Messages Available field.
What if I can see one or more messages in the Message Available field?
Confirm your Queue Name matches what you entered in Threat Stack.
Navigate to the Settings page.
Select the Integrations tab.
In the AWS Accounts module, select the Edit ()icon.
Within the Edit AWS Integration screen, confirm the SQS Source field displays the correct Queue Name.
Within AWS, you can find your Queue Name in the SQS Service area within the AWS Console.
Within Threat Stack, you can find the Queue Name on the Edit AWS Integration screen.
Confirm the region selected in the Edit AWS Integration screen matches the region in the SQS ARN.
Navigate to the Settings page.
Select the Integrations tab.
In the AWS Accounts module, select the Edit () icon.
Within the Edit AWS Integration screen, verify the region in the Select Regions field.
Within the AWS Console, open the Queue details and check the ARN or URL fields.
Within Threat Stack, you can find the region on the Edit AWS Integration screen.
In AWS, review the policy on the 3rd party cross-account IAM role to confirm Threat Stack has permission to read the queue.
What if I can't see any (0) messages in the Message Available field?
Note
Best practice: Redo the integration using the .
Please review the following troubleshooting suggestions:
Confirm the queue subscribes to the proper SNS topic.
Navigate to the SNS.
Confirm that the SNS topic displays the SQS Queue as a subscription endpoint.
Confirm CloudTrail delivers logs properly and sends notifications using the SNS topic.
What if I see the error () icon?
If you experience this issue, it indicates Threat Stack cannot connect to your AWS Account.
Please review the following troubleshooting suggestions and best practices:
Confirm the Role ARN entries match in Threat Stack and AWS.
Navigate to the Settings page.
Select the Integrations tab.
In the AWS Accounts module, locate the ARN column and verify the Role ARN value.
Within Threat Stack, you can find the Role ARN in the AWS Accounts module.
Within AWS, locate the 3rd party cross-account and verify the Role ARN entry.
Confirm the External ID entries match in Threat Stack and AWS.
Navigate to the Settings page.
Select the Integrations tab.
In the AWS Accounts module, locate the External ID column and verify the External ID.
Within Threat Stack, you can find the Role ARN in the AWS Accounts module.
Within AWS, locate the 3rd party cross-account and verify the Role ARN entry.
View ArticleThreat Stacks Threat Intelligence feature correlates the outgoing and incoming IPs out of the host with the Threat Stack curated IP list from various sources.
IP Source Lists
We have both open source and commercial sources
Partial open source list
http://www.dshield.org/ipsascii.html
http://www.dshield.org/block.txt
Partial commercial source list
Iblocklist: iblocklist.com/lists
Configuration Steps
The default threat intelligence rule that comes right off the box captures outgoing traffic (type=connect) and generates a severity 1 alert. The configuration involves three simple steps
Enable the threat intelligence rule under rule sets (please contact support if you do not see the rule set)
Tweak the rule for the right severities and filters (ex - you want to add capture incoming traffic as well and change severities on that)
Associate the rule set with servers you want to see alerts on
Customers can also create new custom rules by following the below steps.
Create a New Threat Intelligence Rule
Customers can create custom threat intelligence rules (click add new threat intelligence rule) based on the below filter keys.
network event types (type = connect or type = accept)
threatintel_source: The fields here are
tscommercial
threatintel_reason
scanning host
spamming host
malicious host
threatintel_type
IP
A custom filter might looks like
type=connect and threatintel_reason=malicious host
Please select aggregations for the alert title to work.
An example is below.
Result Types
Similar to other features, threat intelligence features is manifested in two places - alerts and events.
Events
We generate an event of type threatintel (event_type="threatintel") when there is a IP match with any of the bad IP lists. The event has information on whether the connections is a inbound or outbound, the source of the threat intelligence and the reason. The user can search for any of the corresponding fields as the below examples illustrate.
Alerts
Alerts will be generated if there's a match and you would see them on the alerts screen. The text filtering for the alerts would the threat intelligence.
Contributing Events
After you click on the alert, you would see the contributing event, you would see the details related to the match - the source, the reason and the type.
View ArticleExample Commands and Alerts
Testing your rules allows you to verify that your system is configured properly in Threat Stack.
Threat Stack can monitor file:
Creation
Opening
Modifying
Closing
Deleting
How do I test the FIM rules?
You can test FIM by performing the above actions (examples below) on files within monitored directories. If you need help understanding which directories Threat Stack monitors, refer to the Overview of File Integrity Monitoring article.
Note
This is a limited list of commands to give you an idea of ways to test FIM within Threat Stack.
Command line
Explanation
Example Event Types
vi [filename]
Opens the file withthe vi text editor
access, open, and close
echo [enter text] > secret file
Takes texts and add itto the end of a file.
modify, close, write and open event
wget
Downloads a filefrom the internet.
modify, open, close, and write event
curl
Downloads a filefrom the internet.
modify, open, close, and write event
scp outsidehost:/file secretfile
Copies a file from an outside host to your system.
open, modify, close, and write event
scp secretfile outsidehost:/file
Takes a file from your system and copies it toan outside host.
open, access, and close event
Example
Running the vi command to trigger an event and alert.
Choose a file that should be monitored within Threat Stack
Navigate to that files directory
Type vi [filename]
Result: File opens in vi
To exit vi enter :q
Note
FIM events can take up to a minute to display within the Threat Stack system.
Where can I view my results?
Go to the Alerts tab on the left hand side.
Select the Sev 3 tab to display Severity 3 alerts.
Result: You should see an alert for the event that you triggered.
FIM Troubleshooting Guide
What if Idon'tsee an alert for the event?
Check out the or contact support.
View ArticleThreat Stack Agent & Event Stream Data Overview
This article is designed to help you understand the extensive capabilities of the event stream data collected by the Threat Stack Agent. The examples in this article can help you understand how to better monitor and alert on a few common cloud security use cases.
These are the fundamental ideas for how Threat Stack designed our security monitoring:
Event Processing - the Threat Stack Agent collects events around system, process, and user actions and streams them to the backend application.
Rule Based Identification - to isolate signal from noise, events are processed against system and user-defined Rule Sets to identify critical events of interest.
Alert Notification - identified issues generate alerts which generate notifications.
Alert Management - dismissing or suppressing alerts.
Use Cases
The Threat Stack Agents collects events around user activities, process, host and network events. Our application backend correlates the event stream data to provide a context for common security use cases.
User Access Monitoring
Use Case (1) Events of interest for any user and group modifications (Add/Remove/Modify) on production systems.
How Do I Configure Network Access for the Agent?
Use Case (2) Events for any user privilege escalations, a typical scenario is for customers to have an approved list of sudo users and wants alerting and log trail for any violations.
Use Case (3) Detect unauthorized changes on production system. Only the configuration management agent (Chef, Puppet, Ansible, Salt) is authorized for deploys/file copy/install; track any user violations for change operations.
Use Case (4) Generate detailed events and an audit trail for all users' TTY sessions for activity monitoring.
Use Case (5) Monitoring for any privileged application user accounts usage.
Use Case (6) Abnormal user login/access attempts (rate or login/brute forcing/password attacks).
System Integrity Monitoring
Use Case (1) An unauthorized system kernel module or package is loaded or initialized on production systems (indicators of rootkit, APT type malware).
Use Case (2) Detect for deviations for any changes in authorized Ports/Services (Process binds/open).
Use Case (3) Events for any new process connection states. Typically new ACCEPT/CONNECT, this indicates possible intrusion or command-and-control type of activities for unauthorized connectivity.
Use Case (4) Track any unauthorized or abnormal process Start events by user or processes.
Use Case (5) Audit trail activity for any critical file system changes/reads/transfers and permissions changes.
File Integrity Monitoring
Use Case (1) Monitoring critical credential file access/modifications for misuse/abuse typically indicates insider threat activities.
Use Case (2) Monitor Critical system directories (/boot/, /lib, /usr/lib, /bin/, /sbin, /etc) for new executables or binary replacement/modification typical indicates intrusion or command-and-control activities.
Use Case (3) Monitor unauthorized modifications to system and application configuration files (e.g: sshd.conf, ntp.conf, resolv.conf Apache, MySQL, etc).
Use Case (4) Monitor for any data exfiltration type of activities on critical identified files (OPEN, COPY, TRANSFER) - Insider threat scenarios typically related to stolen credential files, SSH Keys, certificates.
Network Activity Monitoring
Use Case (1) Monitoring for any critical system services changes (NTP, DNS, Syslog) daemon re-configuration/port/destination or source changes.
Use Case (2) Monitoring for any System Application Service changes (Apache, DB Server Binds, Proxy, Application Services).
Use Case (3) Monitoring for insecure protocol usage for System access (Telnet, FTP).
As an example, enter dst_port = 23 or dst_port = 21 in the event search field.
Additional Information
How Does Threat Stack Collect Data and What Data is Collected?
View ArticleIntroduction
This page includes frequently asked questions Threat Stack has received about File Integrity Monitoring (FIM) and the File Transfer Protocol (FTP).
How Do I Use FIM To Monitor a FTP?
You can track a FTP services exfiltrating data away from your system using the Threat Stack FIM monitoring service.
Create a FIM rule to monitor a sensitive file or directory. After you create a FIM rule, if a FTP service copies a file to a remote system an event triggers in Threat Stack and you receive an alert stating the file was opened by the service.
How Do I Whitelist a Particular User in FTP?
To whitelist a particular user, you have to add a suppression to the rule they currently trigger.
Note
Threat Stack stores rules on the host and not the backend. This means rules can take a few minutes to update. Additionally, a rule suppression is not recursive.
On the Alerts page, click the Suppressionbutton.
How to Monitor other Folders for Invalid Users
On the Add New Host Rule Suppression dialog, specify the user to suppress.
Click the Add New Suppression button.
You added a suppression to a ruleset. Going forward, Skyler will not trigger an alert related to this rule.
For more information on Suppressions, see the How do I Suppress Alerts? article.
How Do I Monitor Other Folders For Invalid Users?
To monitor other folders for invalid users:
Create a rule to monitor changes in all home directories.
Create suppressions for each user for their own home directory.
See the article for the full instruction set.
View ArticleRaw events All events ingested by Threat Stack. Threat Stack retains raw events according to your companys retention policy a period of one or three days.
Contributing events Events that trigger alerts. Threat Stack retains contributing events for one calendar year from the date of the triggered alert.
View ArticleIssue
I suppress an event from the Alerts page. When I click the Test Filter button, Idon'tsee any events that match the suppression.
Root Causes
There are two possible causes for this issue:
The event that contributed to the alert falls outside of the retention period.
The Test Filter button connects to the raw events stream, not the contributing events stream. More information on the differences between raw and contributing events here. As a result, Threat Stack only returns potential suppressions that match raw events that fall within your companys event retention policy (one or three days). Contributing events, which Threat Stack retains for one full calendar year from the date of the triggered alert, will not display in the potential suppression results and, if you apply the suppression rule, will not retroactively suppress.
The data in the raw event search is different than the data in the alert search.
The Test Filter button connects to the raw events stream. The raw event search contains augmented data. However, the alert search contains raw data. If you click the Test Filter button on the Alerts page, then Threat Stack is using the raw event search to return potential suppression results. Since the raw event search includes augmented data, it may not return potential suppressions that match raw alert data.
View ArticleThreat Stack user accounts lock out if the user types their password incorrectly too many times. If you are a Threat Stack organization owner, then you receive an email notifying you that a users account is locked out. You sign into the Threat Stack Cloud Security Platform (CSP) to unlock the account.
Log into Threat Stack.
In the left navigation pane, click the Settings tab. The Settings page displays.
Click the Users tab. The Users page displays.
In the row for the locked user account, in the Options column, click the Unlock button.
A notification message displays.
Click the Yes, Unlock Account button. The user account unlocks and the Unlock button no longer displays in the Options column. The user receives an email notifying them that their account is unlocked.
View Article