Threat Stack FAQs | Comparably
Threat Stack is involved in building software to secure cloud Infrastructure. read more
EMPLOYEE
PARTICIPANTS
3
TOTAL
RATINGS
56

Threat Stack FAQs

Threat Stack's Frequently Asked Questions page is a central hub where its customers can always go to with their most common questions. These are the 158 most popular questions Threat Stack receives.

Frequently Asked Questions About Threat Stack

  • Organization Owner

    I set up Threat Stack and invited a user through my Identity Provider (IdP) and theycan'tget in?

    An IdP invitation does not replace the need for a Threat Stack invitation. You have to provision users in IdP and send them an invitation through Threat Stack.

    Why did I lose access to organizations, in which I am a user, after I converted the organization I own to SSO?

    For security reasons, Threat Stack does not allow users to authenticate into multiple organizations that have different authentication protocols.

    If you are a user of multiple organizations that have different authentication protocols, and you convert the organization you own to SSO, Threat Stack removes you from the other organizations.

    Why was a user revoked from my organization after I converted it to SSO?

    For security reasons, Threat Stack removes a user from the SSO converted organization if that user belongs to a Threat Stack Organization in which the authentication protocol differs from that of the organization being converted.

    Everyone

    Why can't I send a user an invite to my Threat Stack organization?

    For security reasons, Threat Stack will not send an invitation to users that have been identified as outside of your IdP.

    When I enter my email, I am automatically logged in, but not as the user with the email I entered into the sign-in. Why does this happen?

    Identity Providers cookie very aggressively. If you, or someone else, has logged in as a different user, and that user also exists in Threat Stack, your IdP automatically tells Threat Stack to log you in as the user associated with your current IdP session.

    To fix this and login as yourself, you can:

    Open a new incognito window

    Clear your cookies at the IdP and Threat Stack

    Identity Providers typically support mappings from a user in the Identity Provider to an email address for a user in the Service Provider (Threat Stack). Using custom mappings, an email address in the IdP can be mapped to a user with a different email address in Threat Stack.

    We recommend that users use the same email address in your IdP as in Threat Stack.

    We enabled SSO for Threat Stack, why am I getting redirected to log in through the basic Threat Stack log in page?

    As part of the authentication process, Threat Stack uses cookies and you may still be cookied to through the OAuth authentication path.

    We recommend that you:

    Open a new incognito window

    Clear your cookies at the IdP and Threat Stack

    Why am I stuck at the Threat Stack login page?

    Use case: I entered my email, was redirected to my IdP, and I logged in successfully. I was redirected to Threat Stack and now I'm stuck at the login page.

    You may not have received an invitation to Threat Stack for your SSO email address. Have your Organization Owner send you a Threat Stack invitation so you can create a new account associated with you SSO email address..

    If no one in your organization can access Threat Stack, this suggests that the SSO was misconfigured for your Threat Stack Account and you should contact our support team.

    Why am I stuck in an infinite loop between my IdP and Threat Stack?

    This suggests that the Threat Stack IdP application was misconfigured, particularly the ACS Redirect Url. Contact your identity provider admin to check IdP configurations.

    I have multiple organizations. How do I convert them all to SSO?

    At this time, converting multiple organizations to SSO requires help from a Threat Stack support team member.

    I was added to my IdP but Ican'tlogin?

    Threat Stack compares users within our application to users authorized in the IdP. To access Threat Stack you must be listed in both places, or we block you from logging in.

    If the email you use for Threat Stack does not match your email in your IdP, contact support.

    I was added to Threat Stack but Ican'tlogin?

    Threat Stack compares users within our application to users authorized in the IdP. To access Threat Stack you must be listed in both places, or we block you from logging in.

    Why was I logged out of Threat Stack even though I was working on something?

    Threat Stack enforces a hard eight hour session timeout for all Threat Stack user accounts, regardless of your activity level or authentication method.

    View Article
  • The Threat Stack Cloud Security Platform (CSP) automatically assigns you with a REST API key. Your API key is a unique identifier that allows you to gain access to Threat Stack API resources.

    Important

    Each user within an organization is assigned a unique API key.

    View Your API Key

    Log into the Threat Stack CSP.

    Click the Settings tab. The General Settings tab displays.

    Click the Application Keys tab. In the REST API Key section, your API key displays.

    Note

    Your organization and user IDs also display in this section.

    Reset Your API Key

    Threat Stack recommends resetting your API key if it is exposed to someone outside of your organization, such as a Threat Stack support request in which you include your API key.

    Log into the Threat Stack CSP.

    Click the Settings tab. The General Settings tab displays.

    Click the Application Keys tab. In the REST API Key section, your API key displays.

    Click the Reset API Key button. The API key resets and changes to a new, unique identifier.

    View Article
  • The Threat Stack Cloud Security Platform (CSP) normalizes the structure of raw events received before batching them for export.

    Linux Agent

    Agent 2.1

    Threat Stack Agent 2.1 includes all of the raw event formats available in Agent 2.0, along with these additional formats.

    Kubernetes Config Event Kubernetes Audit Link

    Event Type

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    Kubernetes

    event

    array

    id

    string

    tsEventType*

    "kubernetesConfig"

    ingestTime

    long

    agentId*

    string

    name

    string

    namespace

    string

    organizationId*

    string

    spec

    array

    role_bindings

    optional object

    targets

    optional array

    name

    string

    namespaces

    string

    type

    string

    roleName

    string

    roleType

    string

    role_policies

    optional array

    apiGroups

    optional array

    items

    string

    resourceNames

    optional array

    items

    string

    resources

    optional array

    items

    string

    verbs

    array

    items

    string

    timestamp*

    long

    type

    "ClusterRole" "Role" "ClusterRoleBindings" "RoleBindings"

    uid

    string

    *The field is searchable with Threat Stack Event Search.

    Event Type

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    Kubernetes

    event

    array

    id

    string

    tsEventType*

    "kubernetesAudit"

    ingestTime

    long

    action

    string

    agentId*

    string

    details

    string

    namespace

    string

    nodeName

    string

    nodeUid

    string

    organizationId*

    string

    resource

    object

    name

    string

    namespace

    string

    type

    string

    uid

    string

    timestamp*

    long

    * The field is searchable with Threat Stack Event Search

    Agent 2.0

    Audit File Host Login ThreatIntel

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "audit"

    ingestTime

    long

    agentId

    string

    args

    array

    element

    string

    arguments

    string

    command*

    string

    connection*

    struct

    addr

    string

    dst_addr

    string

    dst_port

    long

    port

    long

    src_addr

    string

    src_port

    long

    version

    long

    containerId*

    string

    containerImage*

    string

    cwd*

    string

    egid

    long

    euid

    long

    exe

    string

    exit*

    string

    fd*

    long

    gid

    long

    group

    string

    loginuid

    long

    organizationId

    string

    path

    array

    element

    string

    pid

    long

    pod_name*

    string

    pod_uid*

    string

    ppid*

    long

    session

    long

    success*

    boolean

    syscall

    string

    timestamp

    long

    tty*

    string

    type

    string

    "accept" "bind" "connect" "listen" "start"

    uid

    long

    user

    string

    * The value of "audit" > "type" determines whether or not this field displays.

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "file"

    ingestTime

    long

    agentId

    string

    arguments

    string

    command

    string

    events

    array

    element

    string

    file_size

    long

    filename

    string

    gid

    long

    group

    string

    organizationId

    string

    pid

    long

    ppid

    long

    rule_id

    string

    rule_name

    string

    session

    long

    timestamp

    long

    total

    long

    uid

    long

    user

    string

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "host"

    ingestTime

    long

    agentId

    string

    comment

    string

    group

    string

    groups

    array

    element

    string

    hostname

    string

    level

    long

    location

    string

    log

    string

    organizationId

    string

    sigid

    long

    src_ip

    string

    timestamp

    long

    user

    string

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "login"

    ingestTime

    long

    agentId

    string

    exit

    string

    id

    string

    logout**

    string

    organizationId

    string

    pid

    long

    session

    long

    src_host

    string

    src_ip

    string

    timestamp

    long

    tty

    string

    type

    string

    "login" "logout"

    uid

    long

    user

    string

    ** If the value of "audit" > "type" is "logout," then this field displays.

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "threatintel"

    ingestTime

    long

    agentId

    string

    command

    string

    connection

    struct

    addr

    string

    dst_addr

    string

    dst_port

    long

    port

    long

    src_addr

    string

    src_port

    long

    version

    long

    cwd

    string

    event_type

    "threatintel"

    exe

    string

    exit

    string

    fd

    long

    gid

    long

    group

    string

    ip

    string

    is_agent_2

    boolean

    organizationId

    string

    pid

    long

    ppid

    long

    ses

    long

    syscall

    string

    threatintel_event_id

    string

    threatintel_reason

    string

    threatintel_source

    string

    threatintel_type

    "ip"

    timestamp

    long

    tty

    string

    type

    "accept"

    uid

    long

    user

    string

    Agent 1.9

    Audit File Host Login ThreatIntel

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "audit"

    ingestTime

    long

    agentId

    string

    args

    array

    element

    string

    arguments

    string

    command*

    string

    connection*

    struct

    addr

    string

    dst_addr

    string

    dst_port

    long

    port

    long

    src_addr

    string

    src_port

    long

    version

    long

    containerId*

    string

    containerImage*

    string

    cwd*

    string

    egid

    long

    euid

    long

    exe*

    string

    exit*

    string

    fd*

    long

    gid

    long

    group

    string

    loginuid

    long

    organizationId

    string

    path

    array

    element

    string

    pid

    long

    pod_name*

    string

    pod_uid*

    string

    ppid*

    long

    session

    long

    success*

    boolean

    syscall

    string

    timestamp

    long

    tty*

    string

    type

    string

    "accept" "access" "adjtimex" "bind" "brk" "chdir" "chmod" "chown" "clock_gettime" "clock_settime" "close" "connect" "epoll_ctl" "fchmod" "fchown" "fcntl" "finit_module" "flock" "fstat" "ftruncate" "futex" "getdents" "getresgid" "geteuid" "getsockname" "getsockopt" "gettimeofday" "init_module" "inotify_add_watch" "ioctl" "ioprio_get" "listen" "lseek" "lstat" "mkdir" "mmap" "mount" "mprotect" "munmap" "newfstatat" "open" "openat" "pipe" "poll" "pselect6" "pwrite64" "read" "readlink" "readlinkat" "recvfrom" "recvmsg" "rename" "rmdir" "select" "sendmsg" "sendmmsg" "sendto" "setrlimit" "setsockopt" "settimeofday" "setxattr" "shutdown" "start" "stat" "umount2" "unlink" "unlinkat" "unshare" "utimes" "wait4" "write" "writev"

    uid

    long

    user

    string

    * The value of audit > type determines whether or not this field displays.

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "file"

    ingestTime

    long

    agentId

    string

    arguments

    string

    command

    string

    events

    array

    element

    string

    file_size

    long

    filename

    string

    gid

    long

    group

    string

    organizationId

    string

    pid

    long

    ppid

    long

    rule_id

    string

    rule_name

    string

    session

    long

    timestamp

    long

    total

    long

    uid

    long

    user

    string

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "host"

    ingestTime

    long

    agentId

    string

    auid**

    long

    caddr**

    string

    comment

    string

    function**

    string

    group

    string

    groups

    array

    element

    string

    header**

    struct

    id

    long

    milliseconds

    long

    pid

    long

    timestamp

    long

    hostname

    string

    level

    long

    library

    string

    location

    string

    log

    string

    organizationId

    string

    original_library**

    string

    overriding_library**

    string

    pid

    long

    raddr**

    string

    ses**

    long

    sigid

    long

    src_ip

    string

    subj**

    string

    timestamp

    long

    type

    string

    "LD_conflict" "null"

    uid**

    long

    user

    string

    ** If the value of audit > type is LD_conflict, then these fields displays.

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "login"

    ingestTime

    long

    agentId

    string

    command***

    string

    exit_status***

    struct

    code

    long

    termination

    long

    id

    string

    logout***

    string

    new_session_pid

    long

    organizationId

    string

    parent_session***

    long

    pid

    long

    session

    long

    src_host***

    string

    src_ip***

    string

    timestamp

    long

    tty***

    string

    type

    string

    "login" "logout" "session_update"

    uid

    long

    user

    string

    *** The value of login > type determines whether or not this field displays.

    Field

    Field Format

    Subfield

    Subfield Format

    Subfield

    Subfield Format

    event

    array

    id

    string

    tsEventType

    "threatintel"

    ingestTime

    long

    agentId

    string

    args

    array

    element

    string

    arguments

    string

    command

    string

    connection

    struct

    addr

    string

    dst_addr

    string

    dst_port

    long

    port

    long

    src_addr****

    string

    src_port****

    long

    version

    long

    egid

    long

    euid

    long

    event_type

    "threatintel"

    exe

    string

    exit

    string

    fd****

    long

    gid

    long

    group

    string

    ip

    string

    organizationId

    string

    path

    array

    element

    string

    pid

    long

    ppid

    long

    session

    long

    syscall

    string

    threatintel_event_id

    string

    threatintel_reason

    string

    threatintel_source

    string

    threatintel_type

    "ip"

    timestamp

    long

    tty

    string

    type

    string

    "accept" "connect"

    uid

    long

    user

    string

    ****If the value of threatintel > type is accept, then this field displays.

    Windows Agent

    Agent 2.0.0w and beyond

    Note

    Windows events will contain a subset of fields shown in the table below.

    Event Type

    Field

    Field Format

    Subfield

    Subfield Format

    Windows

    event

    array

    id

    string

    tsEventType*

    "winsec"

    type

    "Audit Policy Change" "Computer Account Management" "Credential Validation" "Firewall" "Logon" "Logoff" "Process Creation" "Process Termination" "Security Group Management" "Security State Change" "Security System Extension" "System Integrity" "User Account Management"

    access

    string

    allowed_delegates

    string

    audit_category

    string

    audit_guid

    string

    audit_guid

    string

    audit_policy_changes

    string

    audit_subcategory

    string

    auth_package

    string

    code

    integer

    command

    string

    company

    string

    correlation

    string

    current_directory

    string

    description

    string

    display_name

    string

    dns_host

    string

    dns_results

    string

    dns_status

    integer

    driver

    string

    dst_host

    string

    dst_ip

    string

    dst_ipv6

    boolean

    dst_port

    integer

    dst_port_name

    string

    domain

    string

    elevated

    string

    exe

    string

    execution_pid

    integer

    execution_tid

    integer

    expiration

    string

    file_version

    string

    guid

    string

    hash

    string

    home_directory

    string

    home_path

    string

    impersonation

    string

    integrity_name

    string

    integrity_sid

    string

    key_length

    integer

    linked_logon_id

    integer

    lm_package_name

    string

    audit_guid

    string

    logon_hours

    string

    logon_process

    string

    logon_type

    string

    logon_title

    string

    logout

    string

    new_reg_key

    string

    new_state

    string

    new_time

    string

    new_uac

    string

    new_user_name

    string

    new_value

    string

    net_conn_initiated

    boolean

    notification_package

    string

    old_time

    string

    old_uac

    string

    parent_command

    string

    parent_guid

    string

    parent_name

    string

    password_last_set

    string

    pid

    integer

    pipe_name

    string

    ppid

    integer

    primary_group_id

    string

    principal_name

    string

    privileges

    string

    product

    string

    profile_path

    string

    protocol

    string

    record_number

    integer

    restricted_admin

    string

    reg_event

    string

    sam_account

    string

    script_path

    string

    security_package

    string

    service_account

    string

    service_file

    string

    service_name

    string

    service_start

    integer

    service_type

    integer

    session

    uint32**

    sid

    string

    sid_history

    string

    signature

    string

    signature_validity

    string

    signed

    boolean

    special_groups

    string

    spn

    string

    src_host

    string

    src_ip

    string

    src_ipv6

    string

    src_log

    string

    src_port

    integer

    src_port_name

    string

    start_addr

    string

    start_func

    string

    start_module

    string

    status

    string

    status_string

    string

    subject_domain

    string

    subject_session

    string

    subject_user

    string

    subject_sid

    string

    summary

    string

    target_device

    string

    target_domain

    string

    target_exe

    string

    target_file

    string

    target_group

    string

    target_group_id

    string

    target_guid

    string

    target_outbound_domain

    string

    target_outbound_user

    string

    target_pid

    integer

    target_reg_key

    string

    target_sid

    string

    target_user

    string

    target_server

    string

    target_server_info

    string

    target_session

    string

    terminal_session

    string

    thread_id

    string

    timestamp

    string

    token_elevation_type

    string

    trace

    string

    transmitted_services

    string

    tty

    string

    uac

    string

    user

    string

    user_parameters

    string

    virtual

    string

    win_event_id

    uint16***

    wmi_consumer

    string

    wmi_consumer_type

    string

    wmi_event

    string

    wmi_filter

    string

    wmi_name

    string

    wmi_namespace

    string

    wmi_operation

    string

    wmi_query

    string

    workstation

    string

    *The field is searchable with Threat Stack Event Search.

    ** uint32 is an unsigned integer with 32 bits, which means you can represent 2^32 numbers.

    *** uint16 is an unsigned integer with 16 bits, which means you can represent 2^16 numbers.

    Related Articles

    Data Portability

    View Article
  • You can update a ruleset in the Threat Stack Cloud Security Platform (CSP). Locate the rule by either navigating to the Rules tab or the Alerts tab.

    Note

    If you are looking to create a ruleset, please review the Rule Creation Overview article.

    Updating Through the Rules Tab

    Navigate to the Rules tab and select the rule you would like to update.

    How do I Suppress an Alert?

    The Details pane displays on the right side. You can update the following:

    The rule name

    The alert title

    The alert description

    The aggregate fields

    The frequency of triggering an alert

    Click Update Rule to register your changes.

    Click the Filter link to display the rule filter settings. You can also update your deployment and suppression settings.

    To add a new suppression, click the New Suppression button. For additional information, please review the How do I Suppress an Alert? article.

    After making your selections, make sure to register your changes.

    The updates to the ruleset will be displayed in the Rules tab.

    Updating Through the Alerts Tab

    Navigate to the Alerts tab. Locate the alert associated with the rule you would like to update.

    Note

    In this example, the "User activity (Logins)" alert was selected.

    Click the View/Edit Rule link.

    The Edit Rule dialog displays. Within the Details pane, you can update the following:

    The severity of the alert

    The rule name

    The alert title

    The alert description

    The aggregate fields

    The frequency of triggering an alert

    Note

    In this example, a host rule is being updated.

    You can also update other settings for deployment, rule filter and suppression by clicking their respective tabs.

    To add a new suppression, select the Suppressions tab and click the New Suppression button. For additional information, please review the article.

    After making your selections, make sure to register your changes.

    The ruleset is updated and your changes are displayed in the Threat Stack CSP.

    View Article
  • If you have configured File Integrity Monitoring (FIM) but are unable to view events that trigger alerts in Threat Stack, consider these troubleshooting suggestions or contact support.

    Ensure your server is assigned a ruleset.

    Confirm the specific rule is enabled.

    Confirm the rule is monitoring the expected directory and event type.

    Ensure no suppression is preventing the alert from triggering.

    Verify the rule reached the Agent.

    Verify FIM events are appearing on the Events page.

    Ensure the server does not run CentOS or RHEL 6 ( RHEL 6 and CentOS specific FAQ).

    Is the Ruleset Applied to the Server?

    You can ensure Threat Stack is monitoring the right server.

    In the left navigation pane, click the Servers tab.

    Select the server from the list.

    Verify the correct ruleset displays in the Summary pane.

    Note

    In this example, a Base Rule Set was assigned to the server named "instance-1".

    Confirm the Rule is Enabled

    Navigate to the ruleset and ensure the rule is enabled.

    In the left navigation pane, click the Rules tab.

    Note

    You can also navigate to the ruleset from the Servers page.

    Select a ruleset from the list.

    Note

    In this example, the Base Rule Set was selected.

    Click the Show More link to display additional rules.

    Select a rule from the list.

    Note

    In this example, the Files: Secret File Opens rule is selected.

    Confirm the rule is enabled.

    Note

    Disabled rules will be grayed out and listed at the bottom of the ruleset they belong to.

    Confirm the Rule is Monitoring the Expected Directory and Event Type

    You can inspect the rule and confirm the rule monitors the expected directory and event type(s).

    In the left navigation pane, click the Rules tab.

    Note

    You can also navigate to the ruleset from the Servers page.

    Select a ruleset from the list.

    Note

    In this example, the Base Rule Set was selected.

    Click the Show More link to display additional rules.

    Select a rule from the list.

    Note

    In this example, the Files: Secret File Opens rule is selected.

    Click the File Paths link.

    In the right view pane, the File Paths to Monitor screen is displayed. Confirm the rule is monitoring the expected directory and event type(s), by reviewing the File Integrity Paths field and the Events To Monitor field.

    Confirm No Suppressions are Preventing Alerts fromTriggering

    There could be a suppression preventing an alert from displaying an event. You can confirm whether a suppression is enabled within a rule.

    In the left navigation pane, click the Rules tab.

    Note

    You can also navigate to the ruleset from the Servers page.

    Select a ruleset from the list.

    Note

    In this example, the Base Rule Set was selected.

    Click the Show More link to display additional rules.

    Select a rule from the list.

    Note

    In this example, the Files: Secret File Opens rule is selected.

    Click the Suppressions link.

    In the right view pane, the Suppressions screen is displayed. Review the related suppressions and confirm they do not interfere with your ability to generate an alert.

    Confirm the Rule Reached the Agent

    Connect to your instance.

    Navigate to the following directory:/opt/threatstack/etc/.

    Open the tsfim.config.json file.

    Within this file, under the watchers key find the directories key.

    Its value should be a list of the monitored directories.

    Confirm your directory displays on this monitored list.

    Note

    If you choose to monitor an individual file instead, or in addition to a directory, then it will display in the files key instead of the directories key.

    Example

    The Files: Secret File Opens" rule has Threat Stack monitor the "/fimtesting/" and "/home/ubuntu/.aws/" directories. Threat Stack does not monitor any individual files because the rule does not call for monitoring.

    Confirm Events are Generated and Searchable in Threat Stack

    You can confirm whether the right events are searchable in the Threat Stack Cloud Security Platform (CSP).

    In the left navigation pane, click the Events tab. All raw events are displayed.

    In the Search field, enter the following:

    event_type = "file"

    Note

    File refers to a FIM event in the Threat Stack CSP.

    Click the Date and Time drop-down menu.

    The date and time dialog displays. Click the Quick Jump link.

    Select your desired time period from the available options.

    Note

    Selecting the time period triggers the search in Threat Stack.

    A list of events is displayed.

    Note

    If no search results display, ensure there is no misspelling in your search criteria or select a different time frame.

    View Article
  • Threat Stack user accounts lock out if the user types their password incorrectly too many times. If you are the Threat Stack organization owner, then you receive an email notifying you that a users account is locked out. If you decide not to unlock the account, then you can revoke the account instead. You sign into the Threat Stack Cloud Security Platform (CSP) to revoke the account.

    Log into Threat Stack.

    In the left navigation pane, click the Settings tab. The Settings page displays.

    Click the Users tab. The Users page displays.

    In the row for the user account to revoke, in the Options column, click the Revoke Access button. A notification message displays.

    Click the Yes, Revoke Access button. The user account no longer has access to Threat Stack and no longer displays on the Users page.

    View Article
  • Events that enter the Threat Stack Cloud Security Platform (CSP) are keyword searchable. You can use any field in the event's metadata as a search keyword. You can also use a predetermined set of operators to combine keywords into a refined search query.

    The following sections list keyword searchable fields by event type and the operators you can use to refine search queries. For more information on searching for events, see Search for Events.

    Audit Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    event_type

    The overarching type of the event, as defined by Threat Stack.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    arguments

    List of all arguments in the event.

    auid

    The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.

    command

    The command run that triggered the event.

    connection

    A description of the socket connection made to or from the monitored instance.

    addr

    dst_addr

    dst_port

    port

    src_addr

    src_port

    version

    containerId

    If the event is from a container, then the ID of the container from which the event triggered.

    containerImage

    If the event is from a container, then the title of the container image from which the event triggered.

    cwd

    The path to the directory that invoked the system call that triggered the event.

    egid

    The effective group ID of the user who triggered the event.

    euid

    The effective user ID of the user who triggered the event.

    eventId

    The Threat Stack-generated ID of the event.

    exe

    The path to the executable used to trigger the event.

    exit

    The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.

    exit_status

    The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.

    code

    termination

    fd

    If set, then the file descriptor of the socket that opened for a network connection.

    gid

    The group ID of the user who triggered the event.

    group

    The group of the user who triggered the event.

    header

    The information in the header of the audit message that triggered the event.

    id

    milliseconds

    timestamp

    timestamp

    The UNIX timestamp of when the event triggered.

    is_agent_2

    Indicated whether or not the Agent sending the event is a Threat Stack version 1.x Agent event or a Threat Stack version 2.x Agent event.

    loginuid

    The user ID logged in at the time the event triggered.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    path

    The information about any paths which were passed as an argument to the system call that triggered the event.

    pid

    The process ID attached to the event, as reported by your operating system (OS).

    pod_name

    If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.

    pod_uid

    If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.

    ppid

    The parent process ID attached to the event, as reported by your OS.

    rule_name

    The name of the Threat Stack rule applied to the event.

    session

    The Shell session from which the event triggered.

    success

    A Boolean value that indicates whether or not the action that triggered the event was successful.

    syscall

    The type of system call sent to the kernel.

    tty

    The terminal from which the system call was invoked.

    uid

    The user ID of the user who triggered the event.

    user

    The username of the user who triggered the event.

    CloudTrail Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    Subfield Name

    Subfield Name

    Subfield Name

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    timestamp

    The UNIX timestamp of when the event triggered.

    _insert_time

    The UNIX timestamp of the time the event reached the edge of the Threat Stack CSP.

    event_type

    The overarching type of the event, as defined by Threat Stack.

    eventVersion

    The version of the log event format.

    userIdentity

    Information about the user that made the request.

    type

    userName

    principalId

    arn

    accountId

    accessKeyId

    sessionContext

    attributes

    creationDate

    mfaAuthenticated

    invokedBy

    sessionIssuer

    webIdFederationData

    federatedProvider

    attributes

    eventSource

    The service to which the request was made. The format is typically the short form of the service name + .amazonaws.com, such as cloudformation.amazonaws.com.

    eventSourceType

    eventName

    The requested action. The value returned depends on the actions available through the API for the service.

    accountId

    The account that owns the entity that granted permissions for the request. If the request was made with temporary security credentials, then this is the account that owns the IAM user/role used to obtain credentials.

    arn

    awsRegion

    The AWS region to which the request was made.

    userAgent

    The agent through which the request was made, such as the AWS Management Console, an AWS service, the AWS SDKs, or the AWS CLI.

    bucketName

    error

    errorCode

    If the request returns an error, then the AWS service error number.

    errorMessage

    If the request returns an error, then the AWS service error description.

    responseElements

    The response element for actions that make changes, such ascreate,delete, orupdate.

    assumedRoleUser

    arn

    assumedRoleId

    credentials

    accessKeyId

    requestParameters

    The parameters sent with the request. The parameters are documented in each AWS service's API documentation.

    groupId

    ipPermissions

    items

    fromPort

    ipProtocol

    toPort

    ipv6Ranges

    items (This field is a list of IP addresses)

    roleSessionName

    additionalEventData

    Additional information about the event that is not part of the request or the response.

    requestId

    The value that identifies the request. The serviced called generates this value.

    eventId

    The Threat Stack-generated ID of the event.

    eventType

    The ID of the type of the event that triggered the event.

    apiVersion

    The API version associated with the AwsApiCall eventType value.

    arnRole

    accessKey

    cidrIP

    consoleLogin

    managementEvent

    A Boolean value that indicates whether or not the event is a management event.

    MFAUsed

    readonly

    A Boolean value that indicates whether or not the event is a read-only event.

    resourceName

    resourceType

    resources

    A list of resources accessed in the event.

    ARN

    accountId

    type

    recipientAccountID

    The account ID that received the event.

    serviceEventDetails

    The service event, including the trigger for the event and the result.

    sharedEventID

    The GUID generated by CloudTrail to uniquely identify CloudTrail events from the same AWS action that is sent to different AWS accounts.

    subnetId

    iamInstanceProfileArn

    iamInstanceProfileId

    ip

    imageId

    keyId

    sourceIPAddress

    The IP address from which the request was made.

    permission

    profileId

    policyArn

    feed

    user

    The username of the user who triggered the event.

    userType

    vpcID

    The VPC endpoint in which requests were made from a VPC to another AWS service.

    File Integrity Monitoring (FIM) Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    event_type

    The overarching type of the event, as defined by Threat Stack.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    arguments

    List of all arguments of the command executed that resulted in the filesystem event that triggered the event.

    auid

    The audit user identification (ID) of the user who triggered the event. This ID is assigned at user login and is inherited by every process, even when the user's identity changes.

    command

    The command run that triggered the event.

    containerId

    If the event is from a container, then the ID of the container from which the event triggered.

    containerImage

    If the event is from a container, then the title of the container image from which the event triggered.

    eventId

    The Threat Stack-generated ID of the event.

    events

    The strings that represent the type of event that occurred, such asACCESS, CLOSE, DELETE, MODIFY, and so on.

    exe

    The path to the executable used to trigger the event.

    exit

    The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.

    filename

    The name of the file that triggered the event.

    gid

    The group ID of the user who triggered the event.

    group

    The group of the user who triggered the event.

    timestamp

    The UNIX timestamp of when the event triggered.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    pid

    The process ID attached to the event, as reported by your operating system (OS).

    pod_name

    If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.

    pod_uid

    If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.

    ppid

    The parent process ID attached to the event, as reported by your OS.

    rule_id

    The id of the rule applied to the event.

    session

    The Shell session from which the event triggered.

    tty

    The terminal from which the system call was invoked.

    uid

    The user ID of the user who triggered the event.

    user

    The username of the user who triggered the event.

    Kubernetes Audit Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    Subfield Definition

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    event_type

    The overarching type of the event, as defined by Threat Stack.

    action

    The type of event.

    eventId

    The Threat Stack-generated ID of the event.

    timestamp

    The UNIX timestamp of when the event triggered.

    name

    The namespace in which the object exists.

    node_name

    The name of the node (server) on which the event triggered.

    namespace

    The Kubernetes namespace in which the event triggered.

    resource

    The object on which the event triggered.

    name

    type

    namespace

    type

    The type of record, as reported by either auditd or the OS.

    Kubernetes Config Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    Subfield Definition

    Subfield Name

    Subfield Definition

    Subfield Name

    Subfield Definition

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    event_type

    The overarching type of the event, as defined by Threat Stack.

    action

    The type of event.

    eventId

    The Threat Stack-generated ID of the event.

    timestamp

    The UNIX timestamp of when the event triggered.

    name

    The namespace in which the object exists.

    namespace

    The Kubernetes namespace in which the event triggered.

    type

    The type of record, as reported by either auditd or the OS.

    spec

    The configuration of the object.

    role_bindings

    targets

    name

    type

    namespace

    role_name

    role_type

    role_policies

    verbs

    api_groups

    resources

    resource_names

    Linux Host Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    event_type

    The overarching type of the event, as defined by Threat Stack.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    arguments

    List of all arguments in the event.

    auid

    The audit user identification (ID) of the user who triggered the event. This ID is assigned at user login and is inherited by every process, even when the user's identity changes.

    caddr

    The address in memory from which the symbol for the event loads.

    comment

    A text comment that attempts to provide additional information to the preloaded information for the event.

    eventId

    The Threat Stack-generated ID of the event.

    exe

    The path to the executable used to trigger the event.

    function

    The symbol found to be overloaded.

    group

    The group of the user who triggered the event.

    timestamp

    The UNIX timestamp of when the event triggered.

    level

    The level value from the rule applied to the event.

    library

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    originalLibrary

    The shared object file from which the symbol for the event should have loaded.

    overridingLibrary

    The shared object file from which the symbol for the event currently loads.

    pid

    The process ID attached to the event, as reported by your operating system (OS).

    raddr

    The address of the real symbol for the event that should have been loaded.

    session

    The Shell session from which the event triggered.

    sigid

    The rule ID of the rule applied to the event.

    src_ip

    If set, then indicates the source IP address of the action that triggered the event.

    subj

    uid

    The user ID of the user who triggered the event.

    user

    The username of the user who triggered the event.

    Login Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    event_type

    The overarching type of the event, as defined by Threat Stack.

    address

    The IP address from which the user who triggered the event originated.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    arguments

    List of all arguments in the event.

    auid

    The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.

    command

    The command run that triggered the event.

    containerId

    If the event is from a container, then the ID of the container from which the event triggered.

    containerImage

    If the event is from a container, then the title of the container image from which the event triggered.

    eventId

    The Threat Stack-generated ID of the event.

    exe

    The path to the executable used to trigger the event.

    host

    timestamp

    The UNIX timestamp of when the event triggered.

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    pid

    The process ID attached to the event, as reported by your operating system (OS).

    pod_name

    If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.

    pod_uid

    If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.

    session

    The Shell session from which the event triggered.

    uid

    The user ID of the user who triggered the event.

    user

    The username of the user who triggered the event.

    Threat Intelligence (ThreatIntel) Events: Supported Keywords

    Field Name

    Field Definition

    Subfield Name

    event_type

    The overarching type of the event, as defined by Threat Stack.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    arguments

    List of all arguments in the event.

    auid

    The audit user identification (ID) of the user who triggered the event.This ID is assigned at user login and is inherited by every process, even when the user's identity changes.

    command

    The command run that triggered the event.

    connection

    The description of the socket connection made to or from the monitored instance.

    addr

    dst_addr

    dst_port

    port

    src_addr

    src_port

    containerId

    If the event is from a container, then the ID of the container from which the event triggered.

    containerImage

    If the event is from a container, then the title of the container image from which the event triggered.

    cwd

    The path to the directory that invoked the system call that triggered the event.

    egid

    The effective group ID of the user who triggered the event.

    euid

    The effective user ID of the user who triggered the event.

    eventId

    The Threat Stack-generated ID of the event.

    exe

    The path to the executable used to trigger the event.

    exit

    The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.

    exit_status

    The value that specifies the exit code returned by the system call. The returned value depends on the type of system call.

    code

    termination

    fd

    If set, then the file descriptor of the socket that opened for a network connection.

    gid

    The group ID of the user who triggered the event.

    group

    The group of the user who triggered the event.

    header

    The information in the header of the audit message that triggered the event.

    id

    milliseconds

    timestamp

    timestamp

    The UNIX timestamp of when the event triggered.

    is_agent_2

    Indicated whether or not the Agent sending the event is a Threat Stack version 1.x Agent event or a Threat Stack version 2.x Agent event.

    loginuid

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    path

    The information about any paths which were passed as an argument to the system call that triggered the event.

    pid

    The process ID attached to the event, as reported by your operating system (OS).

    pod_name

    If the event is a Kubernetes event, then the name of the Kubernetes pod from which the system call that triggered the event originated.

    pod_uid

    If the event is a Kubernetes event, then the UID of the Kubernetes pod from which the system call that triggered the event originated.

    ppid

    The parent process ID attached to the event, as reported by your OS.

    rule_name

    The name of the Threat Stack rule applied to the event.

    session

    The Shell session from which the event triggered.

    success

    A Boolean value that indicates whether or not the action that triggered the event was successful.

    syscall

    The type of system call sent to the kernel.

    threatintelEventId

    The ID of the event.

    threatintel_reason

    The reason the IP address is marked as malicious.

    threatintel_source

    The source of information used to determined that the IP address is malicious.

    threatintel_type

    The hardcoded value of the IP address.

    tty

    The terminal from which the system call was invoked.

    type

    The type of record, as reported by either auditd or the OS.

    uid

    The user ID of the user who triggered the event.

    user

    The username of the user who triggered the event.

    Windows Events: Supported Keywords

    Field Name

    Field Definition

    organization_id

    The ID that describes the Threat Stack customer organization that reported the event.

    agent_id

    The Threat Stack Agent's ID that sent the event to the Threat Stack CSP.

    event_type

    timestamp

    The time at which the event triggered.

    addr

    command

    The cli command that triggered the event.

    correlation

    The GUID of the activity that triggered the event.

    dns_host

    The name of the computer as registered in DNS.

    dst_host

    Sysmon: The hostname of the network connection's destination.

    dst_ip

    Sysmon: The destination IP address of the network connection.

    dstIpv6

    Sysmon: A Boolean value which indicates whether or not the IP address in an IPv6 address.

    dst_port

    Sysmon: The port used by the network connection's destination.

    domain

    eventId

    The Threat Stack-generated ID of the event.

    exe

    The filename of the event's triggering or target application.

    guid

    Sysmon: The GUID of a newly-created process. A unique universal identifier.

    hash

    Sysmon: A hash value.

    linked_logon_id

    The ID of a paired login.

    logon_process

    logon_type

    Login type as an INT.

    parent_command

    Sysmon: The cli command used to invoke a new event's parent.

    parent_guid

    Sysmon: The GUID of a new process's parent.

    parent_name

    The name of a new process's parent.

    pid

    The ID attached of an event's triggering or newly created process.

    ppid

    Used for events that create new processes.

    reg_event

    Sysmon: The type of operation performed on the target registry key.

    sam_account

    The SAM account associated with the event, usually account management.

    sid

    A security identifier.

    signature

    Sysmon: The signature of a driver.

    signature_validity

    Sysmon: Integrity of a driver's signature.

    signed

    A Boolean value that indicates whether or not the driver is signed.

    src_ip

    Sysmon: The IP address of a network connection source.

    src_ipv6

    Sysmon: A Boolean value that indicates whether or not a network connection's IP address is IPv6.

    src_port

    Sysmon: The source's port in a network connection.

    target_exe

    Sysmon: The executable affected by this event.

    target_file

    target_guid

    Sysmon: The GUID of a target process.

    target_reg_key

    Sysmon: The registry key affected by this event.

    target_user

    Sysmon: The username of the account affected by this event.

    user

    The name of the user who triggered the event.

    win_event_id

    Supported Operators

    Operator

    Operator Definition

    Example

    =

    include anything that exactly matches the keyword

    exe = "/bin/ls"

    !=

    exclude anything that exactly matches the keyword

    tty != NULL

    <

    include anything fewer than the keyword

    pid < 999

    <=

    include anything fewer than or equal to the keyword

    pid <= 1000

    >

    include anything greater than the keyword

    pid > 999

    >=

    include anything greater than or equal to the keyword

    pid >= 1000

    like

    include anything that matches a string within the keyword

    arguments like "BECOME-SUCCESS"

    and &&

    include anything that matches both the first condition and the second condition of the query

    tty != NULL and tty != "" tty != NULL && tty != ""

    or ||

    include anything that matches either the first condition or the second condition of the query

    tty != NULL or tty != "" tty != NULL || tty != ""

    Related Articles

    Introduction to Events

    Overview: Events Feature

    All Raw Events Tab

    My Event Queue Tab

    Search for Events

    View Article
  • Overview

    This document describes the steps to re-register an Agent not displaying in the Threat Stack Cloud Security Platform (CSP).

    Tip

    If you need to re-register multiple Agents, Threat Stack recommends re-registering one Agent first to ensure the process works as expected. You may then re-register remaining Agents in parallel.

    Linux Agent 1.x Series

    If you log into the Threat Stack CSP and the Servers pagedoes not display the expected number of servers, then you may need to re-register your Agent(s). If you see a "Agent has been revoked. Shutting down" message in /opt/threatstack/cloudsight/logs/cloudsight.log, then you need to re-register your Agent.

    Prerequisites

    Administrator access to your Amazon Web Service (AWS) account

    Access to the Threat Stack console

    Your deployment key, which can be found in Settings > Application Keys

    Instructions

    In the Command Line, type the following command and press ENTER:

    sudo cloudsight stop

    Type the following command and press ENTER:

    sudo rm /opt/threatstack/cloudsight/config/.secret

    Do one of the following:

    To re-register your Agent with the Threat Stack Base Rule Set, type the following command and press ENTER:

    sudo cloudsight setup --deploy-key=<your deploy key>

    Replace <your deploy key> with your deployment key.

    To re-register your Agent with a different Threat Stack ruleset, type the following command and press ENTER:

    sudo cloudsight setup --ruleset=<ruleset name> --deploy-key=<your deploy key>

    Replace <your deploy key> withyour deployment key. Replace<ruleset name> with the Threat Stack Ruleset name, such as HIPAA.

    Note

    You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.

    Type the following command and press ENTER:

    sudo cloudsight start

    Linux Agent 2.x Series

    If you log into the Threat Stack CSP and the Servers pagedoes not display the expected number of servers, then you may need to re-register your Agent(s). If you run the sudo tsagent status command and receive a "1 tsagent: Agent is revoked" message, then you need to re-register your Agent.

    Prerequisites

    Administrator access to your Amazon Web Service (AWS) account

    Access to the Threat Stack console

    Your deployment key, which can be found in Settings > Application Keys

    Your AWS hostname

    Instructions

    Instructions for a Non-revoked Agent

    In the Command Line, type the following command and press ENTER:

    sudo systemctl stop threatstack

    Type the following command and press ENTER:

    sudo tsagent setup --deploy-key=<your deploy key> --ruleset=Base Rule Set --hostname=<your hostname>

    Replace <your deploy key> with your deployment key. Replace <your hostname>with your AWS hostname.

    Note

    You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.

    Type the following command and press ENTER:

    sudo systemctl start threatstack

    Instructions for a Revoked Agent

    In the Command Line, type the following command and press ENTER:

    sudo systemctl stop threatstack

    Type the following command and press ENTER:

    sudo rm /opt/threatstack/etc/tsagentd.cfg

    Type the following command and press ENTER:

    sudo tsagent setup --deploy-key=<your deploy key> --ruleset=Base Rule Set --hostname=<your hostname>

    Replace <your deploy key>with your deployment key. Replace <your hostname>with your AWS hostname.

    Note

    You can specify multiple rulesets for an Agent by including comma separated ruleset names in the ruleset parameter.

    Type the following command and press ENTER:

    sudo systemctl start threatstack

    View Article
  • Once you log into Threat Stack Application Security (AppSec) Monitoring, you download the microagent, run the installer, and add one line of code to your application.

    Download Threat Stack AppSec

    You download Threat Stack AppSec installer from AppSec Monitoring in the Threat Stack Cloud Security Platform (CSP).

    Note

    If your software engineers do not have access to the Threat Stack CSP, then give them one of the following links to download the Threat Stack AppSec installer:

    https://pkg.threatstack.com/appsec/node/bluefyre-agent-node-latest.tgz.

    .

    In the left navigation bar, select the Applications tab. In the right view pane, the AppSec Monitoring page displays.

    Select a project and click theAgents button. The Agents screen displays.

    Click the Download Agent button.

    here

    The Download Agent screen displays.

    In the type of microagent you want to download, click the Download button. The Threat Stack AppSec installer downloads.

    Open the Command Line window and run one of the following command to verify the integrity of the download:

    Node.js:

    {{shasum -a 256 bluefyre-agent-node.tgz

    a70959f1259e425195ad0fb21359c41b36a25bb3d6f1438e4a16b1947c243e69= bluefyre-agent-node-1.2.18.tgz }}

    Python

    {{shasum -a 256 bluefyre_agent_python.tgz

    02546ac9f08dce554adb91cd0fe16fefbe268e2490e36b10ad2cb738afdd3c92 ./bluefyre_agent_python-0.0.8-cp27-cp27m-linux_x86_64.whl

    a3ad218939482343fae5703f0452e840d56eefc0d54bdd1fdf71e1a10f57861d ./bluefyre_agent_python-0.0.8-cp27-cp27mu-linux_x86_64.whl

    1e695d5d067fc93cefd1b8162504192072df9bf8e6bc118dd1579768be057da4 ./bluefyre_agent_python-0.0.8-cp34-cp34m-linux_x86_64.whl

    3e71e861060eaf0053425a9183672d34588f672264db09188e77d429af7e9959 ./bluefyre_agent_python-0.0.8-cp35-cp35m-linux_x86_64.whl

    82b6e48dcd8735abcc949f054d654318607b240789ee28d683bf615c53cc75fb ./bluefyre_agent_python-0.0.8-cp36-cp36m-linux_x86_64.whl

    b61c8c1aa6b59d3b9373112e9ea38b4ce4f9eeef855d990e02204b91a5108f31 ./bluefyre_agent_python-0.0.8-cp37-cp37m-linux_x86_64.whl

    1ec2aeaceaa7c24766bb8a468aa28c0a0307b6b7d0265f843af753e586cabd8a ./bluefyre_agent_python-0.0.8.tar.gz

    }}

    Install Threat Stack AppSec in Your Application Build Package

    You can install Threat Stack AppSec in both Node.js and Python applications.

    Node.js

    Open the Command Line window and go to your Node application.

    Run the following command:

    npm install ./bluefyre-agent-node-x.x.x.tgz

    Threat Stack AppSec installs.

    Python

    Run Application Locally

    Install a virtual environment, such as venv and Python3.7.

    Open the Command Line window and go to your Python application.

    Do one of the following:

    If you use an Linux distribution or a Windows operating system (OS), then use the source distribution to install the application:

    python --versionpip install bluefyre_agent_python-latest.tar.gz

    If you use an Ubuntu distribution, then use the wheel files to install the application:

    python --versionpip install bluefyre_agent_python-latest-cp37-cp37m-linux_x86_64.whl

    Threat Stack AppSec installs.

    Run Application in Production

    If running a production Django app, install the AppSec agent so that it works with a WSGI server, such as gunicorn or uwsgi.

    gunicorn

    BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn web_project.wsgi -b :5001

    gunicorn with a different worker class thread, such as gevent and three workers:

    BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn --worker-class=gevent --worker-connections=1000 --workers=3 web_project.wsgi 0.0.0.0:5000

    Threat Stack AppSec installs.

    Add Threat Stack AppSec to Your Application (Node.js Only)

    Add a single line of code to your Node.js application to include Threat Stack AppSec as a dependent library.

    Open the Command Line window and go to your Node application.

    Go to the entry point of your application, typically the index.js or server.js file.

    In the first line of the file, add the following command:

    var agent = require('bluefyre-agent-node')

    Save the file. Threat Stack AppSec now sends information back to the server when your application runs.

    Set Microagent ID and Run Application

    Once you configure your Threat Stack AppSec project(s) and microagent(s), add a microagent ID to your applications environment. Threat Stack AppSec displays proactive risk identification(s) from your code base and real time attack alerts in the selected microagent.

    Node.js

    Open the Command Line window and go to your Node application.

    Do one of the following:

    Add the following environment variable, which associates your Threat Stack AppSec microagent ID with your application:

    BLUEFYRE_AGENT_ID="YOUR_AGENT_ID_GOES_HERE" npm start

    Replace Your_Agent_ID_Goes_Here with your microagent ID number. Instructions on how to find the microagent ID number are .

    Now, when your application starts, risk factors in your applications code base and detected attacks display in the selected microagent.

    Create a file in the applications root directory called bluefyre.json and include the following commands:

    {

    "agent_id": "YOUR_AGENT_ID"

    "Other Optional Arguments": VALUE

    }

    Replace Other Optional Arguments with one or more of the following commands:

    To automatically block detected SQL injection attacks:

    BLUEFYRE_BLOCK_SQLI=true

    To automatically block cross-site scripting attacks:

    BLUEFYRE_BLOCK_XSS=true

    To exclude specific fields from scanning:

    BLUEFYRE_DROP_FIELDS ="list of fields"

    Replace list of fields with field names.

    Python

    Run Application Locally

    Open the Command Line window.

    To start a Django web application on port 5000, run the following command:

    BLUEFYRE_AGENT_ID=12323231313 bluefyrectl execProgram python minimal.py runserver --noreload 0.0.0.0:5000

    Optionally, specify one or more of the additional variables:

    To automatically block detected SQL injection attacks:

    BLUEFYRE_BLOCK_SQLI=true

    To automatically block cross-site scripting attacks:

    BLUEFYRE_BLOCK_XSS=true

    To exclude specific fields from scanning:

    BLUEFYRE_DROP_FIELDS ="list of fields"

    Replace list of fields with field names.

    Run Application in Production

    Open the Command Line window.

    To start in gunicorn with a different worker class thread, such as gevent and three workers, run the following command:

    BLUEFYRE_AGENT_ID="2234242242" bluefyrectl execProgram gunicorn --worker-class=gevent --worker-connections=1000 --workers=3 web_project.wsgi 0.0.0.0:5000

    Optionally, specify one or more of the additional variables:

    To automatically block detected SQL injection attacks:

    BLUEFYRE_BLOCK_SQLI=true

    To automatically block cross-site scripting attacks:

    BLUEFYRE_BLOCK_XSS=true

    To exclude specific fields from scanning:

    BLUEFYRE_DROP_FIELDS ="list of fields"

    Replace list of fields with field names.

    Troubleshooting Threat Stack AppSec

    As soon as your application is running, view the Agent Timeline page. The Agent Timeline page displays some information in the Environment pane, and the Events in last 24h" pane begins to increment. If you do not see this information, the microagent may not be properly reporting to the AppSec Monitoring service.

    To troubleshoot the issue, you can run in a debug mode and view details.

    Stop the application.

    Open the Command Line window.

    Restart the application with one of the following commands:

    Node.js

    DEBUG='bluefyre:*' npm start

    Python Django

    # django

    DEBUG=true BLUEFYRE_AGENT_ID="23423432424234" LOGLEVEL=DEBUG bluefyrectl execProgram python manage.py runserver --noreload 0.0.0.0:5001

    Python gunicorn

    # gunicorn

    DEBUG=true BLUEFYRE_AGENT_ID="23423432424234" LOGLEVEL=DEBUG bluefyrectl execProgram gunicorn web_project.wsgi -b :5001

    View Article
  • In the Threat Stack Cloud Security Platform (CSP), organization owners and organization users have different privileges. Organization owners have more privileges than organization users. Organization owners and users have the same basic privileges in the Threat Stack CSP, but organization owners exclusively have the following privileges:

    Add, revoke, and delete Threat Stack CSP user accounts.

    Enable, edit, and delete single sign-on (SSO) integrations with the Threat Stack CSP.

    Enable, edit, and delete push notification integrations with PagerDuty.

    Reset your organizations deployment key for Agent installation.

    Change your organizations settings for auto-dismissal of Severity 3 alerts.

    Change your organizations name.

    Add or update billing information for the Threat Stack CSP.

    Tip

    Need a more thorough explanation of the privilege differences between organization owners and users? See this article.

    View Article
  • In the Threat Stack Cloud Security Platform (CSP), organization owners and organization users have different privileges. Organization owners have more privileges than organization users. These organization privileges cannot be configured by any Threat Stack CSP account, whether owner or user.

    Tip

    Just need a quick breakdown of the privilege differences between organization owners and users? See this FAQ.

    Navigation Tabs

    Organization Owner

    Organization User

    View the left navigation pane

    View the left navigation pane

    Switch organizations

    Switch organizations

    Access the Dashboard tab

    Access the Dashboard tab

    Access the Config Audit tab

    Access the Config Audit tab

    Access the Servers tab

    Access the Servers tab

    Access the Alerts tab

    Access the Alerts tab

    Access the Events tab

    Access the Events tab

    Access the Rules tab

    Access the Rules tab

    Access the Audit Log tab

    Access the Audit Log tab

    Access the Applications tab

    Access the Applications tab

    Access the Settings tab

    Access the Settings tab

    View the top navigation pane

    View the top navigation pane

    View the title of the currently selected left navigation tab

    View the title of the currently selected left navigation tab

    View your account avatar

    View your account avatar

    View the email address associated with your account

    View the email address associated with your account

    Log out of the Threat Stack CSP

    Log out of the Threat Stack CSP

    Access the Support menu

    Access the Support menu

    Open a Support ticket

    Open a Support ticket

    View the status of the Threat Stack CSP

    View the status of the Threat Stack CSP

    Access Help and Documentation about the Threat Stack CSP

    Access Help and Documentation about the Threat Stack CSP

    View the Threat Stack CSP's terms of service

    View the Threat Stack CSP's terms of service

    View the Threat Stack CSP's privacy policy

    View the Threat Stack CSP's privacy policy

    Dashboard Tab

    Organization Owner

    Organization User

    Access the Dashboard tab

    Access the Dashboard tab

    View the New Alerts in the Last 24 Hours pane

    View the New Alerts in the Last 24 Hours pane

    Access the Alerts tab > Severity 1 tab

    Access the Alerts tab > Severity 1 tab

    Access the Alerts tab > Severity 2 tab

    Access the Alerts tab > Severity 2 tab

    View the Vulnerable Servers pane

    View the Vulnerable Servers pane

    View the Servers tab > Online Servers tab

    View the Servers tab > Online Servers tab

    View the Coverage Analysis pane

    View the Coverage Analysis pane

    View the Severity 1 Alerts Generated This Week pane

    View the Severity 1 Alerts Generated This Week pane

    Access the Alerts tab > Severity 1 tab

    Access the Alerts tab > Severity 1 tab

    View the Severity 2 Alerts Generated This Week pane

    View the Severity 2 Alerts Generated This Week pane

    Access the Alerts tab > Severity 2 tab

    Access the Alerts tab > Severity 2 tab

    Config Audit Tab

    Organization Owner

    Organization User

    Access the Config Audit tab

    Access the Config Audit tab

    Run a configuration audit assessment

    Run a configuration audit assessment

    View results of a configuration audit assessment

    View results of a configuration audit assessment

    Servers Tab

    Organization Owner

    Organization User

    Access the Servers tab

    Access the Servers tab

    Access the Online Servers tab

    Access the Online Servers tab

    View servers with out of date Agents

    View servers with out of date Agents

    View servers with high CVE

    View servers with high CVE

    Search for servers

    Search for servers

    View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, uptime, and Agent information

    View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, uptime, and Agent information

    Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, uptime, or Agent information

    Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, uptime, or Agent information

    Add Threat Stack Agent series 1.x or 2.x to a server

    Add Threat Stack Agent series 1.x or 2.x to a server

    Select one or multiple server(s)

    Select one or multiple server(s)

    Revoke one or multiple server(s)

    Revoke one or multiple server(s)

    Filter displayed servers by vulnerability severity, AWS EC2 tags, Ruleset, and/or Threat Stack Agent version

    Filter displayed servers by vulnerability severity, AWS EC2 tags, Ruleset, and/or Threat Stack Agent version

    Access the Offline Servers tab

    Access the Offline Servers tab

    View servers with out of date (no longer supported) Agents

    View servers with out of date (no longer supported) Agents

    View servers with high CVE

    View servers with high CVE

    Search for servers

    Search for servers

    View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, last seen, and Agent information

    View server names, vulnerabilities, instance IDs, regions, instance types, key pairs, IP addresses, last seen, and Agent information

    Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, last seen, or Agent information

    Sort by server names, vulnerabilities, instance IDs, regions, instance types, key pairs, last seen, or Agent information

    Add Threat Stack Agent series 1.x or 2.x to a server

    Add Threat Stack Agent series 1.x or 2.x to a server

    Select one or multiple server(s)

    Select one or multiple server(s)

    Revoke one or multiple server(s)

    Revoke one or multiple server(s)

    Filter displayed servers by CVE, vulnerability severity, or AWS EC2 tags

    Filter displayed servers by CVE, vulnerability severity, or AWS EC2 tags

    Access the All EC2 Servers tab

    Access the All EC2 Servers tab

    View non-monitored instances

    View non-monitored instances

    Search for instances

    Search for instances

    View whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, and the instance's internal IP address

    View whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, and the instance's internal IP address

    Sort by whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, or the instance's internal IP address

    Sort by whether or not a Threat Stack Agent is installed on the instance, the instance name, the instance ID, the instance type, the instance region, the instance key pair, the instance's external IP address, or the instance's internal IP address

    Filter displayed servers by EC2 monitored state, EC2 key name, and/or EC2 instance type

    Filter displayed servers by EC2 monitored state, EC2 key name, and/or EC2 instance type

    Access the Vulnerabilities tab

    Access the Vulnerabilities tab

    View active vulnerabilities

    View active vulnerabilities

    View vulnerable packages, CVEs, vectors, servers affected, and vulnerability severity

    View vulnerable packages, CVEs, vectors, servers affected, and vulnerability severity

    Select one or multiple vulnerability(ies)

    Select one or multiple vulnerability(ies)

    Suppress a vulnerability for business reasons, false positive, compensating control in place, or other

    Suppress a vulnerability for business reasons, false positive, compensating control in place, or other

    Suppress all vulnerabilities related to a specific CVE for business reasons, false positive, compensating control in place, or other

    Suppress all vulnerabilities related to a specific CVE for business reasons, false positive, compensating control in place, or other

    Filter vulnerabilities by CVE, package, attack vector, and/or severity level

    Filter vulnerabilities by CVE, package, attack vector, and/or severity level

    View suppressed vulnerabilities

    View suppressed vulnerabilities

    View suppressed vulnerability packages, CVEs, date and time of suppression, and reason for suppression

    View suppressed vulnerability packages, CVEs, date and time of suppression, and reason for suppression

    Select one or multiple suppressed vulnerability(ies)

    Select one or multiple suppressed vulnerability(ies)

    Remove suppressions from vulnerabilities

    Remove suppressions from vulnerabilities

    Alerts Tab

    Organization Owner

    Organization User

    Access the Alerts tab

    Access the Alerts tab

    Access the Alerts Histogram section

    Access the Alerts Histogram section

    Select a time range / clear the time range on the Alerts Histogram

    Select a time range / clear the time range on the Alerts Histogram

    Filter alerts by title

    Filter alerts by title

    Change the displayed number of alerts that match the selected filters

    Change the displayed number of alerts that match the selected filters

    View alerts by group

    View alerts by group

    View the number of alerts in a group, the title of the group, and the trend line for those alerts over the previous seven calendar days

    View the number of alerts in a group, the title of the group, and the trend line for those alerts over the previous seven calendar days

    View subgroups of alerts

    View subgroups of alerts

    View the number of alerts in a subgroup and the title of the subgroup

    View the number of alerts in a subgroup and the title of the subgroup

    Select one or multiple subgroup(s)

    Select one or multiple subgroup(s)

    Dismiss all alerts in a subgroup for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons

    Dismiss all alerts in a subgroup for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons

    Suppress all alerts in a subgroup

    Suppress all alerts in a subgroup

    View alerts in a list

    View alerts in a list

    View an alert's severity, title, and last date and time of the alert

    View an alert's severity, title, and last date and time of the alert

    Sort alerts by severity, title, or last alert date and time

    Sort alerts by severity, title, or last alert date and time

    Dismiss an alert for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons

    Dismiss an alert for no reason, business operation, normal per company policy, required temporarily / for testing and maintenance, or for other reasons

    Suppress one or multiple alert(s)

    Suppress one or multiple alert(s)

    View details of an alert

    View details of an alert

    View the JSON for an alert

    View the JSON for an alert

    View or modify the rule associated with the alert

    View or modify the rule associated with the alert

    View AWS EC2 tags associated with an alert

    View AWS EC2 tags associated with an alert

    View events that contributed to an alert

    View events that contributed to an alert

    Filter alerts by rule, by AWS EC2 tag, and/or by Ruleset

    Filter alerts by rule, by AWS EC2 tag, and/or by Ruleset

    Events Tab

    Organization Owner

    Organization User

    Access the Events tab

    Access the Events tab

    Access the All Raw Events tab

    Access the All Raw Events tab

    View a list of supported query keys and operators

    View a list of supported query keys and operators

    Enter a query to search for specific events

    Enter a query to search for specific events

    Pick the date and time within which to display events

    Pick the date and time within which to display events

    Browse events by page

    Browse events by page

    View event metadata

    View event metadata

    Add event metadata to a query

    Add event metadata to a query

    Create a rule from an event

    Create a rule from an event

    View the JSON for an event

    View the JSON for an event

    Add an event to the My Event Queue tab

    Add an event to the My Event Queue tab

    Access the My Event Queue tab

    Access the My Event Queue tab

    View a list of supported query keys and operators

    View a list of supported query keys and operators

    Enter a query to search for specific events

    Enter a query to search for specific events

    Pick the date and time within which to display events

    Pick the date and time within which to display events

    Browse events by page

    Browse events by page

    View event metadata

    View event metadata

    Add event metadata to a query

    Add event metadata to a query

    View the JSON for an event

    View the JSON for an event

    Remove an event from the My Event Queue tab

    Remove an event from the My Event Queue tab

    Rules Tab

    Organization Owner

    Organization User

    Access the Rules tab

    Access the Rules tab

    Enable / disable Rulesets

    Enable / disable Rulesets

    View Rulesets

    View Rulesets

    View Ruleset details

    View Ruleset details

    View servers using the Ruleset, along with their server name, the specific Ruleset(s) applied, and the last time the server sent a hearbeat

    View servers using the Ruleset, along with their server name, the specific Ruleset(s) applied, and the last time the server sent a hearbeat

    Search for servers that use the Ruleset

    Search for servers that use the Ruleset

    Assign / remove servers from the Ruleset

    Assign / remove servers from the Ruleset

    Add / modify Rulesets

    Add / modify Rulesets

    Delete Rulesets(except the Base Ruleset, which cannot be deleted)

    Delete Rulesets(except the Base Ruleset, which cannot be deleted)

    Enable / disable rules

    Enable / disable rules

    Add rules to the Threat Stack CSP, including Linux Host, FIM, CloudTrail, Threat Intelligence, Windows Host, Kubernetes Audit, and/or Kubernetes Config

    Add rules to the Threat Stack CSP, including Linux Host, FIM, CloudTrail, Threat Intelligence, Windows Host, Kubernetes Audit, and/or Kubernetes Config

    Clone rules

    Clone rules

    Add alert triggers to rules

    Add alert triggers to rules

    Assign severity levels to alert triggers

    Assign severity levels to alert triggers

    Assign AWS EC2 inclusion / exclusion tags to rules

    Assign AWS EC2 inclusion / exclusion tags to rules

    Add filters to rules

    Add filters to rules

    Add suppressions to rules

    Add suppressions to rules

    Assign / remove rules from a Ruleset

    Assign / remove rules from a Ruleset

    Modify rules in a Ruleset

    Modify rules in a Ruleset

    Delete rules from a Ruleset

    Delete rules from a Ruleset

    Audit Log Tab

    Organization Owner

    Organization User

    Access the Audit Log tab

    Access the Audit Log tab

    Pick the date and time within which to display audit logs

    Pick the date and time within which to display audit logs

    Search for specific audit logs

    Search for specific audit logs

    Browse pages of audit logs

    Browse pages of audit logs

    View audit logs

    View audit logs

    View the following information associated with an audit log: email address of the user that triggered the audit action, the source of the audit action, the audit action, a description of the audit action, and the date and time at which the audit action occurred

    View the following information associated with an audit log: email address of the user that triggered the audit action, the source of the audit action, the audit action, a description of the audit action, and the date and time at which the audit action occurred

    View the JSON for an audit log

    View the JSON for an audit log

    Settings Tab

    Organization Owner

    Organization User

    Access the Settings tab

    Access the Settings tab

    General Settings Tab

    Organization Owner

    Organization User

    Access the General Settings tab

    Access the General Settings tab

    Access the General Settings section

    Access the General Settings section

    Add or modify the Full Name for the Threat Stack CSP account

    Add or modify the Full Name for the Threat Stack CSP account

    Add or modify the Organization Name

    Enroll in Multi-Factor Authentication

    Enroll in Multi-Factor Authentication

    Change the current Threat Stack CSP account's password

    Change the current Threat Stack CSP account's password

    Access the Notification Settings section

    Access the Notification Settings section

    Enable / disable email alerts

    Enable / disable email alerts

    Receive daily email reports for: alerts, FIM, vulnerabilities, consolodated compliance information

    Receive daily email reports for: alerts, FIM, vulnerabilities, consolodated compliance information

    Receive email reports for Configuration Auditing, per assessment

    Receive email reports for Configuration Auditing, per assessment

    Modify the number of daily email reports to which the Threat Stack CSP account subscribes

    Modify the number of daily email reports to which the Threat Stack CSP account subscribes

    Access the Alert Settings section

    Enable / disable automatic dismissal of Severity 3 alerts

    Modify the frequency at which Severity 3 alerts are dismissed

    Access the Scheduled Assessments section

    Access the Scheduled Assessments section

    Enable / disable daily configuration audit assessments

    Enable / disable daily configuration audit assessments

    Modify the date and time at which configuration audit assessments occur

    Modify the date and time at which configuration audit assessments occur

    Users Tab

    Organization Owner

    Organization User

    Access the Users tab

    Access the Users tab

    Send email invitations to people to join your Threat Stack CSP organization

    Send email invitations to people to join your Threat Stack CSP organization

    View a list of usernames, email addresses, roles, and creation dates for all organization owner and user accounts

    View a list of usernames, email addresses, roles, and creation dates for all organization owner and user accounts

    Sort by usernames, email addresses, roles, and creation dates for all organization owner and user accounts

    Sort by usernames, email addresses, roles, and creation dates for all organization owner and user accounts

    Revoke an account's access to your Threat Stack CSP organization

    Promote a user account to the organization owner account

    Authentication Tab

    Organization Owner

    Organization User

    Access the Authentication tab

    Enable / disable Single Sign-On (SSO) for the Threat Stack CSP organization

    Modify SSO for the Threat Stack CSP organization

    Application Keys Tab

    Organization Owner

    Organization User

    Access the Application Keys tab

    Access the Application Keys tab

    Access the Deployment Key section

    Access the Deployment Key section

    View and copy the organization's deployment key

    View and copy the organization's deployment key

    Reset the organization's deployment key

    Access the REST API Key section

    Access the REST API Key section

    View and copy the organization's REST API key

    View and copy the organization's REST API key

    Reset the organization's REST API key

    Reset the organization's REST API key

    View and copy the organization's ID

    View and copy the organization's ID

    View and copy the user account's user ID

    View and copy the user account's user ID

    Integrations Tab

    Organization Owner

    Organization User

    Access the Integrations tab

    Access the Integrations tab

    Access the AWS Accounts section

    Access the AWS Accounts section

    Add, view, modify, and delete AWS account integrations

    Add, view, modify, and delete AWS account integrations

    Access the PagerDuty section

    Access the PagerDuty section

    Add, view, modify, and delete PagerDuty account integrations

    Access the Slack section

    Access the Slack section

    Add, view, modify, and delete Slack account integrations

    Add, view, modify, and delete Slack account integrations

    Access the VictorOps section

    Access the VictorOps section

    Add, view, modify, and delete VictorOps account integrations

    Add, view, modify, and delete VictorOps account integrations

    Access the Webhook API section

    Access the Webhook API section

    Add, view, modify, and delete webhook integrations

    Add, view, modify, and delete webhook integrations

    Billing Tab

    Organization Owner

    Organization User

    Access the Billing tab

    Access the Billing tab

    View payment information

    View payment information

    Add or update payment information

    Public API

    REST API V2 information

    Organization Owner

    Organization User

    Access the Rest API V2 overview

    Access the Rest API V2 overview

    Access the Rest API V2 authentication information

    Access the Rest API V2 authentication information

    Access the Rest API V2 time range information

    Access the Rest API V2 time range information

    Access the Rest API V2 pagination information

    Access the Rest API V2 pagination information

    Access the Rest API V2 rate limit information

    Access the Rest API V2 rate limit information

    Access the Rest API V2 HTTP status code overview

    Access the Rest API V2 HTTP status code overview

    Agent Endpoints and Models

    Organization Owner

    Organization User

    Access Agent endpoints and models

    Access Agent endpoints and models

    Access GET List Agents endpoint

    Access GET List Agents endpoint

    Access GET Get an Agent endpoint

    Access GET Get an Agent endpoint

    Access Agent model

    Access Agent model

    Alert Endpoints and Models

    Organization Owner

    Organization User

    Access Alert endpoints and models

    Access Alert endpoints and models

    Access Alerts overview information

    Access Alerts overview information

    Access GET List Alerts endpoint

    Access GET List Alerts endpoint

    Access GET Get an Alert endpoint

    Access GET Get an Alert endpoint

    Access GET Get Count of Active Alerts by Severity endpoint

    Access GET Get Count of Active Alerts by Severity endpoint

    Access GET Get Events for an Alert endpoint

    Access GET Get Events for an Alert endpoint

    Access POST Dismiss Alerts endpoint

    Access POST Dismiss Alerts endpoint

    Access Alert model

    Access Alert model

    Access Alert Severity Count model

    Access Alert Severity Count model

    Access Dismiss Alert by ID model

    Access Dismiss Alert by ID model

    Access Dismiss Alert by Query Parameters model

    Access Dismiss Alert by Query Parameters model

    Audit Log Endpoints and Models

    Organization Owner

    Organization User

    Access Audit Logs endpoints and models

    Access Audit Logs endpoints and models

    Access GET Audit Logs endpoint

    Access GET Audit Logs endpoint

    Access Audit Log model

    Access Audit Log model

    Data Portability Endpoints and Models

    Organization Owner

    Organization User

    Access Data Portability endpoints and models

    Access Data Portability endpoints and models

    Access GET List S3 Export Enrollment endpoint

    Access GET List S3 Export Enrollment endpoint

    Access PUT Update S3 Export Enrollment endpoint

    Access PUT Update S3 Export Enrollment endpoint

    Access DELETE Delete S3 Export Enrollment endpoint

    Access DELETE Delete S3 Export Enrollment endpoint

    Access S3 Export Enrollment model

    Access S3 Export Enrollment model

    Access Update S3 Export Enrollment model

    Access Update S3 Export Enrollment model

    Rulesets and Rules Endpoints and Models

    Organization Owner

    Organization User

    Access Rulesets and Rules endpoints and models

    Access Rulesets and Rules endpoints and models

    Access Rules and Rulesets overview information

    Access Rules and Rulesets overview information

    Access GET List Rulesets endpoint

    Access GET List Rulesets endpoint

    Access GET Get a Ruleset endpoint

    Access GET Get a Ruleset endpoint

    Access GET List Rules for a Ruleset endpoint

    Access GET List Rules for a Ruleset endpoint

    Access GET Get a Rule for a Ruleset endpoint

    Access GET Get a Rule for a Ruleset endpoint

    Access GET List Active Agents for Rulests endpoint

    Access GET List Active Agents for Rulests endpoint

    Access GET Get Tags for a Rule endpoint

    Access GET Get Tags for a Rule endpoint

    Access POST Create Ruleset endpoint

    Access POST Create Ruleset endpoint

    Access POST Create Rules endpoint

    Access POST Create Rules endpoint

    Access POST Set Tags for a Rule endpoint

    Access POST Set Tags for a Rule endpoint

    Access PUT Update Ruleset endpoint

    Access PUT Update Ruleset endpoint

    Access PUT Update Rule endpoint

    Access PUT Update Rule endpoint

    Access PUT Update Rule Suppression endpoint

    Access PUT Update Rule Suppression endpoint

    Access DELETE Delete Ruleset endpoint

    Access DELETE Delete Ruleset endpoint

    Access DELETE Delete Rule endpoint

    Access DELETE Delete Rule endpoint

    Access IDS Rule model

    Access IDS Rule model

    Access IDS Rule Response model

    Access IDS Rule Response model

    Access File Rule model

    Access File Rule model

    Access File Rule Response model

    Access File Rule Response model

    Access Kubernetes Audit Rule model

    Access Kubernetes Audit Rule model

    Access Kubernetes Audit Rule Response model

    Access Kubernetes Audit Rule Response model

    Access Kubernetes Config Rule model

    Access Kubernetes Config Rule model

    Access Kubernetes Config Rule Response model

    Access Kubernetes Config Rule Response model

    Access Ruleset model

    Access Ruleset model

    Access Windows Rule model

    Access Windows Rule model

    Access Windows Rule Response model

    Access Windows Rule Response model

    EC2 Instance Endpoints and Models

    Organization Owner

    Organization User

    Access EC2 Instances endpoints and models

    Access EC2 Instances endpoints and models

    Access EC2 Instance overview information

    Access EC2 Instance overview information

    Access GET List AWS EC2 Instances endpoint

    Access GET List AWS EC2 Instances endpoint

    Access EC2 Instance model

    Access EC2 Instance model

    CVE Vulnerabilities Endpoints and Models

    Organization Owner

    Organization User

    Access CVE Vulnerabilities endpoints and models

    Access CVE Vulnerabilities endpoints and models

    Access CVE Vulnerabilities overview information

    Access CVE Vulnerabilities overview information

    Access GET List Vulnerabilities endpoint

    Access GET List Vulnerabilities endpoint

    Access GET List Affected Servers by CVE endpoint

    Access GET List Affected Servers by CVE endpoint

    Access GET List Vulnerabilities by Package endpoint

    Access GET List Vulnerabilities by Package endpoint

    Access GET List Suppressions with Details endpoint

    Access GET List Suppressions with Details endpoint

    Access Suppressed CVE Reason model

    Access Suppressed CVE Reason model

    Access Vulnerable Server model

    Access Vulnerable Server model

    Access CVE model

    Access CVE model

    Alert Webhooks API

    Organization Owner

    Organization User

    Access Alert Webhooks API information

    Access Alert Webhooks API information

    Access Webooks overview

    Access Webooks overview

    Access Webooks setup information

    Access Webooks setup information

    Access Webhooks Payload model

    Access Webhooks Payload model

    Access Webooks security information

    Access Webooks security information

    Access Webooks retries information

    Access Webooks retries information

    Access Webook endpoints information

    Access Webook endpoints information

    View Article
  • Release Announcement

    Release Date 11/22/2019

    Threat Stack enhanced the following features in the 11/22/2019 API release:

    Added the Kubernetes Audit Rule model and the Kubernetes Audit Rule Response model

    Added the Kubernetes Config Rule model and the Kubernetes Audit Config Response model

    Release Date 10/25/2019

    Threat Stack enhanced the following features in the 10/25/2019 API release:

    Updated the Webhooks Payloads model to use the correct server_or_region parameter.

    Updated the Webhooks Overview to include [IP address]:[port] format.

    Release Date 10/21/2019

    Threat Stack enhanced the following features in the 10/21/2019 API release:

    Added the Windows Rule model.

    Added the Windows Rule Response model.

    Archived Release Information

    2019 API Releases

    Release Date 10/10/2019

    Threat Stack enhanced the following features in the 10/10/2019 API release:

    Updated Create Rule endpoint to use the correct spelling in the example.

    Updated Create Rule endpoint to use the correct information in alertDescription.

    Release Date 9/17/2019

    Threat Stack enhanced the following features in the 9/17/2019 API release:

    Updated S3 Export Enrollment endpoint with the correct heading.

    Updated Update S3 Export Enrollment endpoint with the correct heading.

    Updated Delete S3 Export Enrollment endpoint with the correct heading.

    Updated Affected Servers by CVE endpoint with correct spelling.

    Release Date 8/9/2019

    Threat Stack enhanced the following features in the 8/9/2019 API release:

    Updated List All Agents with correct spelling.

    Updated Alert Webhooks API Retries with correct spelling.

    Release Date 7/16/2019

    Threat Stack enhanced the following features in the 7/16/2019 API release:

    Updated List All CVEs endpoint with correct spelling.

    Release Date 6/28/2019

    Threat Stack enhanced the following features in the 6/28/2019 API release:

    Updated Dismiss Alert by Query Parameters endpoint with the seven day batch information.

    Updated Dismiss Alerts endpoint with the seven day batch information.

    Updated Rate Limit information with correct parameter spelling for organizationId.

    Release Date 5/8/2019

    Threat Stack enhanced the following features in the 5/8/2019 API release:

    Updated Webhooks Setup with new IP addresses.

    Updated Dismiss Alerts endpoint with the seven day batch information.

    Updated Rate Limit information with correct parameter spelling for organizationId.

    Release Date 4/4/2019

    Threat Stack enhanced the following features in the 4/4/2019 API release:

    Added Set Tags for a Rule endpoint.

    Updated Get Tags for a Rule endpoint to include exclusion tag parameters.

    Release Date 3/18/2019

    Threat Stack enhanced the following features in the 3/18/2019 API release:

    Updated Dismiss Alert endpoint

    Added note to include either a severity, ruleId, or agentId when you dismiss alerts by query, or you receive a 400 error message

    dismissReason parameter now displays the correct capitalization for allowed values

    Updated Create Rule Set and Update Rule Set endpoints' Request Bodies with the correct `ruleIds` parameter

    Release Date 2/13/2019

    Threat Stack enhanced the following features in the 2/13/2019 API release:

    Added S3 Export Enrollment model

    Added Update S3 Export Enrollment endpoint

    Release Date 2/11/2019

    Threat Stack enhanced the following features in the 2/11/2019 API release:

    Added Audit Log model

    Updated Audit Logs endpoint to change the userName property to theuserEmailproperty.

    View Article
  • The Threat Stack Cloud Security Platform (CSP) automatically assigns your organization a deployment key. Your deployment key is a unique identifier that allows Threat Stack Agents to properly connect to the Threat Stack CSP.

    View Your Organizations Deployment Key

    Log into the Threat Stack CSP with your organization owner account.

    Click the Settings tab. The General Settings tab displays.

    Click the Application Keys tab. In the Deployment Key section, your organizations deployment key displays.

    Reset Your Organizations Deployment Key

    Threat Stack recommends resetting your organizations deployment key if it is exposed to someone outside of your organization, such as a Threat Stack support request in which you include your deployment key. Only organization owners can reset deployment keys.

    Log into the Threat Stack CSP with your organization owner account.

    Click the Settings tab. The General Settings tab displays.

    Click the Application Keys tab. In the Deployment Key section, your organizations deployment key displays.

    Click the Reset Deployment Key button. The deployment key resets and changes to a new, unique identifier. Your existing hosts or containers remain connected to the Threat Stack Agent, but any hosts or containers you connect in the future will need to use the new deployment key.

    View Article
  • This document describes configuration steps for deploying the Threat Stack host-based Agent in your Amazon Machine Image (AMI) environment.

    Agent 1.x Series

    Do not run the cloudsight setup command as part of your Amazon Machine Image (AMI) build process. The cloudsight setup command registers the Agent with the Threat Stack service. This registration process assigns a custom token to the Agent. If you include the cloudsight setup command as part of your AMI build process, then the same Agent token will be included on every system deployed using that AMI. This means that multiple Agents will report as a single Agent in the Threat Stack Cloud Security Platform.

    To prevent an AMI from including a registered Agent, follow these steps:

    As part of your AMI build process, install the Threat Stack Agent using the apt or yum process described in the Deploy the Threat Stack Agent article.

    Warning

    Do not install the Threat Stack Agent using curl as this registers the Agent.

    Create the AMI.

    When you deploy the AMI, as part of your node provisioning or as part of the Amazon User Data run the cloudsight setup --deploy-key=<your deploy key> command.

    Replace <your deploy key> with your Threat Stack Agent deploy key. When your client boots up it registers and starts the Threat Stack Agent.

    Agent 2.x Series

    Do not run the tsagent setup command as part of your Amazon Machine Image (AMI) build process. The tsagent setup command registers the Agent with the Threat Stack service. This registration process assigns a custom token to the Agent. If you include the tsagent setup command as part of your AMI build process, then the same Agent token will be included on every system deployed using that AMI. This means that multiple Agents will report as a single Agent in the Threat Stack Cloud Security Platform.

    To prevent an AMI from including a registered Agent, follow these steps:

    As part of your AMI build process, install the Threat Stack Agent using the apt or yum process described in the Deploy the Threat Stack Agent article.

    Warning

    Do not install the Threat Stack Agent using curl as this registers the Agent.

    Create the AMI.

    When you deploy the AMI, as part of your node provisioning or as part of the Amazon User Data run the tsagent setup --deploy-key=<your deploy key> command.

    Replace <your deploy key> with your Threat Stack Agent deploy key. When your client boots up it registers and starts the Threat Stack Agent.

    Run the systemctl disable threatstack command to ensure the Agent does not attempt to start upon boot up of the instance.

    After running the tsagent setup command, update the User Data script to include the systemctl enable threatstack command.

    This will ensure the Threat Stack Agent comes up upon subsequent boots.

    View Article
  • Overview

    This document describes the installation and configuration steps for the Threat Stack host-based Windows Agent 2.x series.

    Pre-Installation for the Threat Stack Agent

    Before you install the Threat Stack host-based Agent, please ensure your environment supports one of the following Windows Server Operating System versions:

    Windows Server 2012 R2

    Windows Server 2016

    Windows Server 2019

    Installing the Threat Stack Agent

    Prerequisites

    Access to the Threat Stack Cloud Security Platform (CSP).

    Ensure you have administrator privileges on the host to perform the installation.

    Begin Agent Download

    Click the Latest Windows Installer button to download the Agent software.

    Once you have downloaded the installer, select one of the installation methods below.

    Windows Setup Installation

    Navigate to the location of the Threat Stack Cloud Security Agent.msi file.

    Double click the file to run it.

    A setup wizard window will appear. Click Next to continue with the installation.

    Sysmon configuration file

    The next screen will display a configuration page, where you can update the following settings:

    The default installation location

    By default, it is "C:\Program Files\Threat Stack\". Click Change to browse to a location of your choice.

    The Threat Stack URL

    By default, it is https://app.threatstack.co m.

    The Ruleset Name

    By default, it is set to Windows Rule Set. You can include multiple rule sets by separating them with a comma.

    For example, to include a Windows and a PCI ruleset, enter the following (Do not include the period at the end): Windows Rule Set, PCI Rule Set.

    The Deployment Key

    A deployment key is required to complete the installation. It is available by logging into your Threat Stack CSP. Navigate to the Settings page and click the Application Keys tab. The key will be displayed under the Deployment Keysection.

    By default, the option for Start the services after setup is complete is checked.

    You can uncheck this option. The services will be installed butwon'tstart until the host is rebooted.

    After entering your organizations deployment key click Next.

    Once you have reviewed your selections and are ready to proceed, click Install.

    Note

    If you have administrator privileges but are not logged into your administrator account, the Install button will show a User Account Control (UAC) shield.

    Once the installation is complete, a confirmation message will appear on the screen. Click Finish to close the window.

    To confirm the Agent is running on the host, open a command prompt. Enter the following command from the install directory and press ENTER:

    tsagent status

    Your newly installed server will appear in the Threat Stack CSP on the Serverspage.

    Command Line Installation

    The Agent can be installed from the command line by either using Windows PowerShell or a Command Prompt. The example below shows the installation process using the Command Prompt.

    Open the Command Prompt Window as an administrator.

    Enter the following command and press ENTER:

    msiexec /qn /i "c:\path\to\threatstack.msi" TSDEPLOYKEY="<DEPLOY_KEY>"

    The command line parameters are as follows:

    C:\path\to\threatstack.msi - Indicates the location of the msi installer.

    For example, if the installer was saved in the Downloads folder on your server, you will enter C:\Users\Administrator\Downloads\threatstack.msi.

    TSDEPLOYKEY - It indicates the deployment key used to register with the platform. Replace <DEPLOY_KEY> with your deployment key.

    A deployment key is required to complete the installation. It is available by logging into your Threat Stack CSP. Navigate to the Settings page and click the Application Keys tab. The key will be displayed under the Deployment Key section.

    TSEVENTLOGLIST (optional) - You can choose to capture System Monitoring (Sysmon) events by adding TSEVENTLOGLIST=Security,Microsoft-Windows-Sysmon/Operationalto the command line.

    TSCLOUDURL (optional) - It indicates the URL of the Threat Stack CSP.

    By default, it is https://app.threatstack.com.

    TSRULESETNAMES (optional) - It indicates the rule set(s) being used.

    It defaults to the Windows Rule Set. You can include multiple rule sets by separating them with a comma.

    For example, to include a Windows and a PCI rule set, enter the following (Do not include the period at the end): TSRULESETNAMES=Windows Rule Set, PCI Rule Set.

    TSSTARTSERVICES (optional) - You can set the Threat Stack Agent (tsagent) service to not start after the installation by adding TSSTARTSERVICES=No to the command line.

    The services will start once the host has been rebooted.

    INSTALLDIR (optional) - It indicates the installation location.

    By default, it is "C:\Program Files\Threat Stack\".

    The installation will quietly run in the background. Once complete, it will return a new command line.

    To confirm the Agent is running on the host, enter the following command from the install directory and press ENTER:

    tsagent status

    Your newly installed server will appear in the Threat Stack CSP on the Servers page.

    System Monitoring (Sysmon) Installation and Configuration

    The Threat Stack Windows Agent leverages Sysmons functionality to focus on security related events. The majority of rules within the Windows Ruleset rely on Sysmon logs. Hence, we recommend installing System Monitoring for optimal performamce of the Windows Agent and its associated rules. For customers who choose not to install Sysmon, the functionality of the Windows Agent becomes very limited. The Agent will still be able to monitor the system (host) via File Integrity Monitoring (FIM) and a subset of events from the Security event log.

    Given the volume of information logged by Sysmon, it is best to apply a configuration file that filters out normal operating system processes and common applications that generate vast amounts of data. We recommend using this Sysmon configuration file.

    Download Sysmon

    Review this Microsoft article for a description of functionality and configuration of Sysmon.

    Click the Sysmon Download button to download the Sysmon files.

    The downloaded Sysmon.zip file contains 3 files:

    Eula.txt - An end user license agreement file.

    Sysmon.exe - A 32-bit Sysmon binary used for installing on 32-bit operating systems.

    Sysmon64.exe - A 64-bit Sysmon binary used for installing on 64-bit operating systems.

    The configuration of Sysmon can be a challenging task due to some of the complexity and logic available to end users. Threat Stack recommends starting with a popular and well commented .

    Install Sysmon

    Open the Command Line window.

    Enter the following command and press ENTER:

    Sysmon64.exe accepteula i sysmonconfig-export.xml

    Note

    The command in this example assumes you downloaded the Sysmon configuration file to the same folder where you extracted your Sysmon.zip file.

    Once installed, Sysmon will start writing logs to a newly created Event Log. You can view the log within Event Viewer by navigating to Applications and Services Logs > Microsoft > Windows > Sysmon > Operational.

    This log file defaults to a maximum size of approximately 65 megabytes (MB). It will rewrite the oldest logs once this limit is reached.

    This default size should be sufficient for most customers.

    Configure the Threat Stack Agent

    Open the Command Line window.

    Enter the following command to enable monitoring of both the Security and Sysmon Event Logs. Then, press ENTER:

    tsagent config --set EventLogs Security,Microsoft-Windows-Sysmon/Operational

    Enter the following command to restart the Agent. Then, press ENTER.

    tsagent restart

    View Article
  • Organization owners can configure the automatic dismissal of Severity 3 alerts to suit their organizations needs. All dismissed alerts are accessible in the Threat Stack Cloud Security Platform (CSP).

    Enable Automatic Dismissal of Severity 3 Alerts

    Log into the Threat Stack CSP with your organization owner account.

    Click the Settings tab. The General Settings tab displays.

    In the Alert Settings section, slide the Auto-dismiss Severity 3 alerts toggle to the right.

    From the Automatically dismiss Severity 3 alerts once they are [X] days old drop-down menu, select the number of days the alert remains in your Threat Stack CSP before automatic dismissal.

    Note

    The default setting is 30 days. Severity 3 alerts can be dismissed up to 90 days after being triggered.

    After making your selection, click the Update Alerts Settings button.

    Note

    It may take up to 24 hours for the first set of old alerts to be dismissed.

    To confirm your selection:

    Navigate to the Alerts page.

    Select the Sev 3 tab.

    Click the expand / collapse button.

    The Dismiss pane displays, confirming the automatic dismissal of alerts is enabled.

    Disable Automatic Dismissal of Severity 3 Alerts

    Log into the Threat Stack CSP with your organization owner account.

    Click the Settings tab. The General Settings tab displays.

    In the Alert Settings section, slide the Auto-dismiss Severity 3 alerts toggle to the left.

    Click the Update Alerts Settings button.

    Severity 3 alerts will no longer be automatically dismissed. You can always re-enable this setting.

    View Article
  • You can manage users through your Threat Stack Cloud Security Platform (CSP) organization owner account.

    Inviting Users

    Log into Threat Stack at https://app.threatstack.com.

    In the left navigation pane, click Settings. The Settings page displays.

    Click the Users tab. The Users page displays.

    In the Invite Users section, in the Enter email for invitation field, type the invitees email address.

    Click the Send Email button. The user receives an email with instructions on setting up an account with Threat Stack.

    https://app.threatstack.com

    Removing Users

    Log into Threat Stack at .

    In the left navigation pane, click Settings. The Settings page displays.

    Click the Users tab. The Users page displays.

    In the Manage Users section, click the Revoke Access button for the user you would like to remove from your account.

    View Article
  • If you want to rename your Threat Stack Cloud Security Platform (CSP) organization for any reason, such as your corporate naming conventions changed, then your organization owner can change your organizations name.

    Log into the Threat Stack CSP with your organization owner account.

    Click the Settings tab. The General Settings tab displays.

    In the Organization Name field, type a new name for your organization.

    Click the Update My Profile button. The organization name updates. No additional integrations or settings need to be changed for the update to take effect.

    View Article
  • You can create a Kubernetes audit rule in the Threat Stack Cloud Security Platform (CSP).

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Life Cycle of an Alert

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.

    The Add Host Rule dialog displays.

    Select Kubernetes Audit Rule from the list and click Next: Details to proceed.

    The Add Kubernetes Audit Rule dialog displays. You will be able to specify the rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the article.

    After making your selection, click Next: Filter.

    The Kubernetes Audit Rule Filter pane displays.

    After specifying a rule filter, click Create Rule.

    The rule will be created and it will be displayed on the Rules page.

    View Article
  • You can create a Kubernetes configuration rule in the Threat Stack Cloud Security Platform (CSP).

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Life Cycle of an Alert

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.

    The Add Host Rule dialog displays.

    Select Kubernetes Config Rule from the list and click Next: Details to proceed.

    The Add Kubernetes Configuration Rule dialog displays. You will be able to specify the rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the article.

    After making your selection, click Next: Filter.

    The Kubernetes Configuration Rule Filter pane displays.

    After specifying a rule filter, click Create Rule.

    The rule will be created and it will be displayed on the Rules page.

    View Article
  • Threat Stack collects raw event data from the Agents installed on your machines and delivers it to the Threat Stack Cloud Security Platform (CSP) to be processed. Then, we utilize the Base Ruleset and any rules you created to trigger alerts based on information you want reported.

    This article explains the types of event rules and the syntax associated with the events. This information will enable you to search for events more efficiently, and make better suppressions and rule filters to refine the information you see inside of Threat Stack.

    Rule Categories

    Threat Stack provides the following rule categories based on the following event types.

    Types

    Event type rules process....

    Audit

    Syscall events from the audit framework

    CloudTrail

    AWS CloudTrail events

    File

    Local file system events for file integrity monitoring

    Host

    Events triggered from host logs

    Windows

    Windows Agent events

    Login

    Local login events

    Threat Intel

    IP reputation events

    Kubernetes Audit

    Kubernetes orchestration events

    Kubernetes Configuration

    Kubernetes configuration events

    Search Syntax Best Practices

    This section includes best practices that apply to searching across all event types:

    The search field is case sensitive.

    You can use parentheses when searching multiples of the same:

    parameters

    key value pairs

    The Alert Details section enables a Add to Search option. It adds key values to your search with the correct syntax.

    The server syntax for agent is consistent across all event types for rules. It searches for the "hostname".

    Note

    Threat Stack uses the CloudTrail native case for compatibility reasons. This means the test filter is case sensitive and uppercase letters will cause the test filter not to match even if a suppression or rule filter is actually correct.

    Audit Event Syntax

    Audit event syntax contains a readable, parseable version of Linux syscalls. This provides a comprehensive look into all local actions taken by your operating system.

    To search an audit event, enter event_type = audit into the search field. You can use AND or OR operators to add key values to your search.

    Notable key value pairs for audit events include:

    Title (Type)

    Key Value Pairs

    Made Connection (type = connect)

    src_addr, src_port, dst_port, ip, port, service, exe, user, group, PID, PPID, command, session

    Accepted connection (type = accept)

    src_addr, src_port, ip, port, exe, user, group, PID, PPID, command, session

    Start (type = start)

    exe, cwd, user, group, PID, PPID command, session, arguments

    Bind Name to Socket (type = bind)

    ip, port, exe, user, group, PID, PPID, command, session

    Listen for socket connections (type = listen)

    exe, user, group, PID, PPID, command, session

    Load a kernel module (type = finit_module)

    exe, user, group, PID, PPID, command, session

    Get & set socket options (type = setsockopt)

    exe, user, group, PID, PPID, command, session, tty

    IP and Port fields are derived fields and are different for connect and accept events.

    Title (Type)

    Key Value Pairs

    Threat Stack Use

    Notes

    Connect

    IP and dst_port

    The IP field is the destination ip of the connection. The port is the destination port (dst_port).

    Accept

    IP and dst_port

    The IP field is the source IP of the remote connection. The port is the ephemeral (negotiated) return port for the tcp connection.

    Network events are TCP connections only and do not include UDP connections.

    CloudTrail Event Syntax

    To search for a CloudTrail event, enter event_type = cloudtrail into the search field.

    Due to the large number of CloudTrail events and key value pairs available and generated, Threat Stack does not index them all. This means, you cannot search every potential value pair. In rare cases, there could be information you want to search, filter, or suppress where you would need to contact us to implement.

    Warning

    CloudTrail is case sensitive for key value pairs. Examples include eventSource, eventName, user, and arnRole.

    Using operators such as like, ends_with, or starts_with, automatically make queries lowercase within Threat Stack which causes the search to fail. This only pertains to event searches not to rule cloning and creation, rule filters, or suppressions.

    Notable CloudTrail Keys

    server

    region

    requestID

    eventID

    arnRole

    accountId

    timestamp

    event_type

    ip

    eventName

    eventSource

    eventSourceType

    Note

    AWS does not provide a CloudTrail validation API endpoint. This means Threat Stack cannot distinguish between key value pairs that are not indexed or invalid key value pairs.

    File Event Syntax

    To search for a file integrity monitoring event, enter event_type = file into the search field.

    Common search would be by filename, command, argument, or user.

    Title (type)

    Key Value Pairs

    File (event_type = file)

    filename, command, arguments, or user

    Host Event Syntax

    To search for host events, enter event_type = host into the search field.

    Login sessions: open and close

    Privilege escalations: successful and failed

    Failed login sessions

    Key Value Pairs

    users

    group

    src_ip

    Search by users, group (have to know exactly what you are looking for syntax wise authentication-success or authentication_failed or invalid_login otherwise the search will fail), or source IP (src_ip).

    Note

    Threat Stack differentiates between privilege escalation failed and a failed login session.

    You can also search for the sigid. It can differentiate within privilege escalation.

    Windows Event Syntax

    To search for Windows events, enter event_type = winsec into the search field.

    Key Value Pairs

    exe

    parent_name

    command

    dst_ip

    src_ip

    Login Event Syntax

    To search for login events, enter event_type = login into the search field.

    Common searches for login events include src_ip, "server" or src_host. Logout events are covered as Host events.

    Key Value Pairs

    src_host

    agent

    src_ip

    Threat Intel Event Syntax

    Threat Intel refers to Threat Intelligence. You can search for Threat Intel events using event_type = threatintel in the search field.

    There are three important key value pairs: threatintel_source, threatintel_reason, and ip. You can determine what list it came from (source), what is the reputation (reason), and the location it came from (ip).

    Key Value Pairs

    user, command, arguments, port

    threatintel_source, threatintel_reason, ip

    Kubernetes Audit Event Syntax

    To search for Kubernetes audit events, enter event_type = kubernetesAudit into the search field.

    Key Value Pairs

    action (Orchesttration action taken on cluster)

    resource.type (Type of resource: pod, node, namespace)

    Kubernetes Configuration Event Syntax

    To search for Kubernetes configuration events, enter event_type = kubernetesConfig into the search field.

    Key Value Pairs

    namespace

    role_name

    role_type

    verbs

    View Article
  • When creating a new rule, you have the option of selecting aggregations. The idea behind aggregation is to group alerts by a defined term. Aggregate fields define the uniqueness of the alert.

    For example, if I built a host rule and set it to aggregate on "src_ip", and then run 11 commands from my local machine, I will see one alert in the Threat Stack Cloud Security Platform (CSP).

    You can also define a time window for when the aggregation should occur. For additional information about alerts and aggregate fields, please review the Life Cycle of an Alert article.

    Aggregate fields are available in the Threat Stack CSP for the following rule types:

    Linux Host Rule

    Aggregate Fields

    exe

    user

    arguments

    ip

    port

    command

    session

    src_ip

    dst_ip

    src_user

    dst_user

    filename

    File Integrity Rule

    Aggregate Fields

    command

    filename

    user

    exe

    arguments

    session

    src_user

    dst_user

    CloudTrail Rule

    Aggregate Fields

    user

    eventName

    eventSource

    ip

    accountId

    Threat Intelligence Rule

    Aggregate Fields

    threatintel_source

    threatintel_reason

    threatintel_type

    ip

    Windows Host Rule

    Aggregate Fields

    command

    correlation

    dns_host

    dst_host

    dst_ip

    dst_ipv6

    dst_port

    exe

    guid

    sam_account

    src_ip

    src_ipv6

    src_addr

    src_port

    user

    sid

    Kubernetes Audit Rule

    Aggregate Fields

    action

    node_name

    namespace

    resource

    name

    type

    Kubernetes Configuration Rule

    Aggregate Fields

    name

    namespace

    type

    role_name

    role_type

    verbs

    View Article
  • Overview

    The Threat Stack Cloud Security Platform (CSP) monitors your infrastructure for risky behavior and configurations. It provides real-time threat detection across your cloud workloads and alerts you of non-compliant changes to your infrastructure.

    The Dashboard displays a comprehensive summary of your alerts, vulnerable servers, and monitored cloud profiles. The information provided enables you to take immediate action while ensuring your organizations compliance needs are met.

    Select the image to enlarge it.

    Note

    Threat Stack supports cloud providers such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).

    Accessing the Dashboard

    You can access the Dashboard through your Threat Stack account.

    Log into Threat Stack at https://app.threatstack.com.

    In the Email field, type your account email address and click Next.

    In the Password field, type your account password and click Next.

    Note

    If you do not remember your password, click the Forgot my password link. You will receive a password reset email containing instructions on how to reset your password.

    Once you are successfully logged in, the Dashboard displays.

    It is the default view in the Threat Stack CSP.

    The Dashboard

    The Dashboard contains the following panes:

    New Alerts in the Last 24 Hours - Displays the number of Severity 1 and Severity 2 alerts that were triggered within the past 24 hours. Click View Alerts to view a list of all active alerts.

    Vulnerable Servers - Displays the number of servers with high or medium rated vulnerabilities. Click View Servers to view a list of vulnerable servers.

    Coverage Analysis - Displays a summary of the number of agents deployed, the number of AWS and non-AWS servers being monitored, along with any unmonitored EC2 instances.

    Note

    Agents deployed using Kubernetes and containers could affect the total number of Agents displayed in the Coverage Analysis pane.

    Severity 1 Alerts Generated This Week - Displays a graph showing the number of Severity 1 alerts generated during the most recent week.

    Severity 2 Alerts Generated This Week - Displays a graph showing the number of Severity 2 alerts generated during the most recent week.

    Select the image to enlarge it.

    For more information about alerts, please see the Alert Feature Overview article.

    View Article
  • Audit

    CloudTrail

    File Integrity Monitoring (FIM)

    Kubernetes Audit

    Kubernetes Configuration

    Linux Host

    Login

    Threat Intelligence (ThreatIntel)

    Windows Host

    Related Articles

    Introduction to Events

    Overview: Events Feature

    All Raw Events Tab

    My Event Queue Tab

    Search for Events

    Supported Keys and Operators

    View Article
  • Most organizations receive thousands of events per day. You can search for events to quickly focus on the most important or relevant information you receive.

    There are two ways to search for events in the Threat Stack CSP:

    Keyword and operator search Use specific keywords and operators to find events that match your search criteria.

    Date and Time picker Select specific dates and times within which to find events. By default, the Threat Stack CSP displays events that occurred during the previous six hours.

    Keyword and Operator Search

    You can search for specific events using keywords in the event metadata, such as user, timestamp, or session identification (ID). You can then use an operator to specify the specific keyword match, such as a username, a specific date and time, or a specific session ID number.

    You can use keywords two ways:

    Add metadata from an event to your search query

    Type keywords into your search query

    Add Event Metadata to Your Search Query

    The Threat Stack CSP helps you quickly add event metadata to a search query. This allows you to find other events that occurred on the same server IP address or at the same date and time or by the same user, among other options.

    Note

    The Threat Stack CSP translates some metadata field names to other information in the search query. This is a result of the event normalization that occurs when events are ingested by the Threat Stack CSP. The following event metadata field names change in the search query:

    server changes to agent_id (Audit, FIM, Linux Host, Login, ThreatIntel) or profile_id (CloudTrail)

    PID changes to pid

    PPID changes to ppid

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Find the event you want to use as the basis for your search.

    Supported Keys and Operators

    Next to the field you want to add to your search query, click the Expand button. The + Add to search menu displays.

    Click + Add to search. The Threat Stack CSP adds the metadata to the search query field.

    Repeat steps four and five for any other metadata you want to add to the search query. For more information on creating a usable search query, see Supported Keys and Operators.

    Type Keywords into Your Search Query

    The Threat Stack CSP matches search criteria to the following keys:

    event_type

    ip

    type

    cwd

    pid

    domain

    arguments

    port

    timestamp

    level

    ppid

    file_size

    src_ip

    dst_ip

    protocol

    user

    command

    exe

    src_port

    dst_port

    agent

    groud

    sigid

    filename

    The Threat Stack CSP uses the following comparison operators:

    =

    !=

    like

    >

    <

    >=

    <=

    The Threat Stack CSP also uses the following logical operators:

    and

    or

    &&

    ||

    For more information, see Supported Keys and Operators.

    Tip

    If you need examples of keywords and operators, then click the Search icon to open the Search Language Tutorial dialog.

    Date and Time Picker

    The Date and Time picker allows you to select the start and end calendar dates, hours, and minutes within which to display events. By default, the previous six hours of events display. You cannot select a date and time later than the current date and time.

    Tip

    The Threat Stack CSP retains events for three calendar days.

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Click the Date and Time picker.

    The Date and Time picker dialog displays.

    On the calendar, click the date by which to start filtering. Available dates display in black font.

    Click the date by which to stop filtering. If you only want to display events for one day, then click the same day twice.

    To select the time, do one of the following:

    To select a predetermined time window:

    Click the Quick Jump link.

    Several specific time frames display.

    Click a time frame button.

    Click the Apply button. The start and end times change to match the selection.

    To use the Hour and Minute slider bars:

    On the left calendar (start), click and drag the HR slider bar until the correct hour displays.

    Click and drag the MIN slider bar until the correct minute displays.

    On the right calendar (end), click and drag the HR slider bar until the correct hour displays.

    Click and drag the MIN slider bar until the correct minute displays.

    Click the Apply button. The start and end times change to match the selection.

    Search Results

    Search results display below your search criteria. By default, the Threat Stack CSP displays all events that occurred during the previous six hours.

    There are three key components to search results:

    Results Found The Results Found field displays the total number of events that match your search criteria.

    Pages Pages display when more than 20 events match your search criteria. Click a page number button / First button / Previous button / Next button to go to a different page of search results.

    Event Details Detailed metadata displays for each event that matches your search criteria. For more information, see All Raw Events Tab > Event Details.

    Related Articles

    Introduction to Events

    Overview: Events Feature

    All Raw Events Tab

    My Event Queue Tab

    View Article
  • The My Event Queue tab displays all events added to your queue using the Add to My Queue button. On the My Event Queue tab, you can search for and work with events in your queue.

    Supported Keys and Operators

    Tip

    Users often add events that provide evidence of suspicious or malicious activity to their queue.

    Events on the My Event Queue tab remain in your queue until you remove them from the queue. However, since the event is now in your queue, it can only be searched for in the My Event Queue tab it is no longer searchable in the All Raw Events tab.

    Search for Events

    You can search for specific events in the My Event Queue tab. For more information, see [hyperlink to Search for Events].

    Event Details

    Each event added to the queue includes metadata related to the action the event records. The event details displayed depend on the source of the event. For more information, see All Raw Events Tab > Event Details.

    View an Event's JSON

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Click the My Event Queue tab. The My Event Queue tab displays.

    Hover the mouse cursor over the event for which to view the JSON. The action bar displays.

    Click the View JSON button. The Event JSON dialog opens.

    Remove an Event from Queue

    Remove events from your queue when they are no longer relevant to your workflow. If the event is still within the three day retention period, then it redisplays on the All Raw Events tab. If the event is outside of the three day retention period, then, if the event is not tied to an alert, it is removed from the Threat Stack CSP.

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Click the My Event Queue tab. The My Event Queue tab displays.

    Hover the mouse cursor over the event to remove from the queue. The action bar displays.

    Click the Remove Event button. The event no longer displays in the queue.

    Related Articles

    Introduction to Events

    Overview: Events Feature

    All Raw Events Tab

    Search for Events

    View Article
  • The All Raw Events tab displays every single event ingested by the Threat Stack CSP within the specified date range. On the All Raw Events tab, you can filter and work with events.

    Note

    The Threat Stack CSP retains events for three days. Events that trigger an alert are retained for 365 calendar days.

    Search for Events

    For more information, see [hyperlink to Search for Events].

    Event Details

    Each event ingested by the Threat Stack CSP includes metadata related to the action the event records. The event details displayed depend on the source of the event.

    Supported Keys and Operators

    Date and Time and Source Icon The date and time at which the event entered the Threat Stack CSP. The icon indicates the source of the event (Threat Stack Agent, CloudTrail, Kubernetes, or Windows).

    Colored dot Indicates the source of an event. This is a quick way to visually distinguish events of particular importance to your workflow.

    Metadata The data collected by the Threat Stack CSP about the event. The source of the event determines the data collected.

    You can perform the following actions from an event:

    Create a rule based on the event

    View the JSON file for the event

    Add events to the My Event Queue tab

    Add event metadata to your search query

    Create a Rule from an Event

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Hover the mouse cursor over the event from which to create a rule. The action bar displays.

    Click the Create Rule button. The Add New [type of rule] Rule dialog opens.

    Follow the instructions in the Rule Creation Overview article for the type of rule to create the new rule.

    View an Event's JSON

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Hover the mouse cursor over the event for which to view the JSON. The action bar displays.

    Click the View JSON button. The Event JSON dialog opens.

    Add Event to My Event Queue Tab

    Click the Add to My Queue button to add an event to the My Event Queue tab. For more information, see My Event Queue.

    Log into the Threat Stack CSP.

    Click the Events tab. The Events screen displays.

    Hover the mouse cursor over the event to add to the My Event Queue tab. The action bar displays.

    Click the Add to My Queue button. A message displays in the lower right corner of the screen informing you that the event has been added to the My Event Queue tab. From now on, you can only search for the event in the My Event Queue tab.

    Related Articles

    Introduction to Events

    Overview: Events Feature

    My Event Queue Tab

    Search for Events

    View Article
  • A vast amount of events occur in your infrastructure every single second. The Threat Stack Cloud Security Platform (CSP) helps you view, organize, and find events of interest to your security concerns within this array of information.

    To assist you in this work, the Events tab contains the following information:

    All Raw Events tab Displays every single event ingested by the Threat Stack CSP within the specified date range. For more information, see All Raw Events Tab.

    Note

    The Threat Stack CSP retains events for three days. Events that trigger an alert are retained for 365 calendar days.

    My Event Queue tab Displays any event you select for further review. For more information, see [hyperlink to My Event Queue].

    Search for Events A variety of criteria you can use to search for and display selected events. For more information, see [hyperlink to Search for Events].

    Supported Keys and Operators

    What Events Does the Threat Stack CSP Ingest?

    Audit

    CloudTrail

    File Integrity Monitoring (FIM)

    Kubernetes Audit

    Kubernetes Configuration

    Linux Host

    Login

    Threat Intelligence (ThreatIntel)

    Windows Host

    Related Articles

    Introduction to Events

    All Raw Events Tab

    My Event Queue Tab

    Search for Events

    View Article
  • Events are the backbone of your cybersecurity operation. Events record everything taking place in your infrastructure. The Threat Stack Cloud Security Platform (CSP) ingests events and assists you in creating a baseline normal, everyday activity. If an event deviates from the baseline, then a Rule triggers an Alert to tell you about potentially malicious activity. Events, therefore, are critical to protecting your infrastructure.

    What Is an Event?

    Events are individual actions that take place within your infrastructure. Events contain metadata related to the action, such as an event identification (ID), the date and time the event took place, and the action taken for example, command or exe. See Overview: Events Feature for a specific list of the types of events the Threat Stack CSP ingests.

    You apply rules to events as they enter your Threat Stack CSP. If the metadata in the event matches an applied rule, then an Alert triggers. Threat Stack ties the event to the alert, which makes it easier to identify the source of potentially anomalous behavior in your infrastructure.

    Where Do I Find Events in the Threat Stack Application?

    Events display on the Events tab in the Threat Stack CSP.

    Supported Keys and Operators

    Why Do I See Events in My Threat Stack CSP?

    The events you see in your Threat Stack CSP record actions taking place in your infrastructure. Events are stored for three calendar days. Events tied to alerts are stored for one calendar year.

    Related Articles

    Overview: Events Feature

    All Raw Events Tab

    My Event Queue Tab

    Search for Events

    View Article
  • To clone an existing rule:

    Log into the Threat Stack Cloud Security Platform (CSP).

    Click the Rules tab.

    In the ruleset from which to clone the rule, click the +New Rule button.

    Select Clone Existing Ruleand click Next: Details.

    Do one of the following:

    Use the search bar to find the rule you want to clone.

    Select the check box next to the name of a rule from the list of rules.

    Once you have selected all the rules you want to copy, click the Clone Rule button.

    Note

    Suppressions will be cloned with the rule you select.

    View Article
  • Threat Stack's Threat Intelligence rule types will alert you to suspicious connections using a curated list of IP addresses from various sources. Threat Stack monitors your environment with the Agent installed, alerting you to problem package installs. For additional information about Threat Stack's Threat Intelligence feature, please review the Threat Intelligence Feature Overview article.

    You can create a Threat Intelligence rule in the Threat Stack Cloud Security Platform (CSP).

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Automatically Integrate with AWS using CloudFormation

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Threat Intelligence Rule Set.

    The Add Host Rule dialog displays.

    Select Threat Intelligence Rule from the list and click Next: Details to proceed.

    The Add Threat Intelligence Rule dialog displays. You will be able to specify the rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.

    After making your selection, click Next: Filter.

    The Threat Intelligence Rule Filter pane displays.

    Tip

    If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.

    However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.

    After specifying a rule filter, click Create Rule.

    The rule creates and displays on the Rules page.

    View Article
  • A file integrity rule will alert you to changes to critical files on your system. You can configure File Integrity Monitoring (FIM) in the Threat Stack Cloud Security Platform (CSP). For additional information about FIM, please review the Overview of File Integrity Monitoring article.

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Automatically Integrate with AWS using CloudFormation

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.

    The Add Host Rule dialog displays.

    Select File Integrity Rule from the list and click Next: Details to proceed.

    The Add File Rule dialog displays. You will be able to specify the file rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.

    After making your selection, click Next: File Paths.

    The File Rule Paths pane displays. You can specify file paths to monitor.

    Note

    Enabling recursive monitoring for a specific file path allows Threat Stack to monitor changes in that directory andall of its subdirectories.

    Tip

    If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.

    However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.

    After specifying a file path and FIM events to monitor, click Create Rule.

    The rule creates and displays on the Rules page.

    View Article
  • Threat Stack collects raw event data from the Agents installed on your machines and delivers it to the Threat Stack Cloud Security Platform (CSP) to be processed. Threat Stack uses the rules you create to initiate alerts based on the information you want reported. Your defined suppressions determine whether you are notified about behavior you consider normal.

    Rulesets can be considered buckets, inside of which rules are built. Suppressions are then associated with the rule directly. In most cases, a server must be associated with a ruleset bucket in order for an alert to be initiated by a rule (This currently excludes CloudTrail rules which rely on tags).

    The following rule types can be configured in the Threat Stack CSP.

    Creating a Kubernetes Configuration Rule

    Host Rule (Linux or Windows)

    Host rules monitor events generated from general activity in the Operating System (OS). Examples include kernel activity, network activity, and user activity. For additional information about configuring a host rule, please review the following articles:

    Creating a Linux Host Rule

    Creating a Windows Host Rule

    File Integrity Rule

    File rules are for monitoring file changes and integrity of the files themselves. In addition to creating the rule, you need to define the path and the events to monitor.

    Examples include file opens, file deletes, configuration file changes, and system file changes. For additional information about configuring a file integrity rule, please review the Creating a File Integrity Rule article.

    CloudTrail Rule

    A CloudTrail rule is a rule built specifically to monitor your connected Amazon Web Services (AWS) CloudTrail service.

    Examples of CloudTrail rules include IAM policy changes, too many API calls, and access denied. For additional information about configuring a CloudTrail rule, please review the Get Started with CloudTrail Alerting article.

    Threat Intelligence Rule

    Threat Stack provides a database of known threats and helps you reference them to keep you safe.

    Examples of Threat Intelligence rules are inbound or outbound IP connections, or system vulnerabilities unveiled after an Agent scan. For additional information about configuring a threat intelligence rule, please review the Creating Threat Intelligence Rule Types article.

    Clone Existing Rule

    This is an opportunity to clone current rules and alter them, or update them to catch new events. For additional information, please review the Clone Existing Rule article.

    Kubernetes Audit Rule

    Kubernetes Audit rules monitor events generated from orchestration activity related to node/pod/container actions, such as creations and modifications. For additional information about configuring a Kubernetes Audit rule, please review the Creating a Kubernetes Audit Rule article.

    Kubernetes Configuration Rule

    Kubernetes Config rules monitor role, role bindings, and cluster role bindings events generated periodically. For additional information about configuring a Kubernetes Configuration rule, please review the article.

    View Article
  • A Host rule will alert you to user activity on your system. You can add a host rule in the Threat Stack Cloud Security Platform (CSP).

    Note

    If you are looking to update a ruleset, please review the Updating a Ruleset article.

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Automatically Integrate with AWS using CloudFormation

    The Add Host Rule dialog displays.

    Select Host Rule from the list and click Next: Details to proceed.

    The Add Host Rule dialog displays. You will be able to specify the rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.

    After making your selection, click Next: Filter.

    The Host Rule Filter pane displays.

    Tip

    If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.

    However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.

    After specifying a rule filter, click Create Rule.

    The rule creates and it displays on the Rules page.

    View Article
  • You can create a File Integrity Monitoring (FIM) rule with a specific user suppression to monitor changes in certain folders by unauthorized users. To do so, perform the following actions:

    Create a rule to monitor changes in all home directories

    Create suppressions for each user for their own home directory

    Create a FIM Rule to Monitor a Folder

    You can create a File Integrity Rule to monitor changes to a folder.

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    How do I Suppress an Alert?

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.

    The Add Host Rule dialog displays.

    Select File Integrity Rule from the list and click Next: Details to proceed.

    The Add File Rule dialog displays. You will be able to specify the file rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.For additional information, please review the Life Cycle of an Alert article.

    Complete the fields for Rule Name, Alert Title and Alert Description. Click the Aggregate Fields to display the drop-down menu. Select User from the list.

    After making your selection, click Next: File Paths.

    The File Rule Paths pane displays. You can specify file paths to monitor

    Specify a File Integrity Path and select the checkbox for Recursive monitoring.

    Note

    Enabling recursive monitoring for a specific file path allows Threat Stack to monitor changes in that directory and all of its subdirectories.

    Click the Events To Monitor field to display the drop-down menu. Select ALL from the list.

    Tip

    If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.

    However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    After specifying a file path and FIM events to monitor, click Create Rule.

    The rule creates and it displays on the Rules page.

    Add a User Specific Suppression to a FIM Rule

    Follow these instructions to remove monitoring for users in their own home directory.

    Within the Rules tab, click the Suppressions link to display the Suppressions pane.

    Click the + New Suppression button.

    The suppression text field is displayed.

    After specifying your suppression filter options, click the Add New Suppression button.

    The suppression saves to the rule.

    Related Articles

    Creating a File Integrity Rule

    View Article
  • Overview

    This article reviews the life cycle of an alert to help you better understand how to perform the following actions:

    Create a rule

    Maximize the effectiveness of that rule

    Review an alert

    Resolve an alert

    Use Case

    You want to create a rule that shows a Severity 2 alert when 5 'sudo' commands happen in an hour. This rule has Threat Stack generate an alert anytime a user escalates their privileges on the monitored host using the `sudo` command.

    The alert life cycle starts when you create a rule on the Threat Stack Rules page.

    1. Create a Rule

    Every rule must include the following components:

    Rule Name: It indicates the name of the ruleset.

    Alert Title: It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. See Rule Aggregation for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame.

    Rule Filter : It indicates the criteria the filter is using to decide if an alert should display.

    Severity: There are three levels of behaviors to indicate the severity of the alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Note

    You should select the aggregation fields that match the substitution fields in the alert title (For example, if you want to substitute "exe" and "user" dynamically with the "user" and "executable", you should select user and exe as the aggregation fields).

    Example of Rule Creation

    The example below walks you through the process of cloning and modifying an existing "Privilege Escalations" rule in the Base Ruleset. You can clone an existing rule by navigating to the Rules page.

    Click the + New Rule button.

    How do I Suppress an Alert?

    The Add Host Rule dialog displays.

    Select Clone Existing Rule and click the Next: Details button.

    In the Select existing rules to clone field, search and select the existing Privilege Escalations rule.

    After making your selection, click the Clone 1 Rule button.

    The cloned rule will be displayed in the rules list.

    You can confirm the Severity of alerts associated with the rule. If necessary, change the severity level by clicking the severity button for your desired alert level.

    In the right view pane, the Details screen displays. You can make changes to the following:

    Rule Name

    Alert Title

    Alert Description

    Aggregate Fileds

    Frequency of alert

    Note

    In the Aggregate Fields, confirm you have the correct aggregations selected.

    In this example, the following updates were made:

    The Rule Name field was updated to Sudo five in an hour {{exe}} by {{user}} with arguments {{arguments}}.

    The Alert Title field was updated to User Activity (Sudo five in an hour) {{exe}} ran by user {{user}} with {{arguments}}.

    The Alert Description field was updated to This alert tracks all sudo ran by a non-root user and alerts you if users run 5 sudo commands in an hour.

    The alert frequency field was updated to 5 times, and the time window for the alert was updated to 1 hour.

    Click the Update Rule button to save your changes.

    Navigate to the Rule Filter pane.

    In the Filter field enter the following filter criteria: command = "sudo" and type ="start".

    Click the Update Rule Filter button .

    You have successfully created a new rule.

    2. Maximize the Effectiveness of the Rule

    When you create a rule, you have the option to select aggregations, alert thresholds, and a time window.

    Aggregation Field

    Aggregate fields define the uniqueness of the alert.

    In our example for rule creation, we selected "execute" and "arguments" as aggregations. Hence, if a user executes the same command within the same argument more than once, Threat Stack considers it an identical event and updates the original alert within the alert threshold.

    Within the context of aggregation, if a user performs the same execution but enters a different argument, a new unique alert displays since Threat Stack considers it a different alert.

    Alert Thresholds

    The alert threshold counts the number of times an event matches the defined filter and aggregations. It displays an alert only after the count matches the alert criteria.

    In our example, we had you set the alert threshold as "5 events in a 1 hour period". This means, if a user executes the same argument 5 times within an hour then Threat Stack generates only 1 alert.

    Time Window

    The time window is the span of time specified to generate an alert based on the number of times an event was executed.

    In our example, if the same alert generates more than once within a time window, Threat Stack would update the existing alert instead of generating a new alert. When Threat Stack updates an existing alert, it attaches the event to the alert record for you to review.

    You can learn more about alerts in the Threat Stack Dashboard in the "Review an Alert" section below.

    3. Review an Alert

    At this point you have created a rule and specified the criteria for an alert. We can now review what an alert looks like on the Alerts page if an event triggers it.

    The Alerts Page

    As a reminder, the Alerts page contains:

    Organized view (default and customizable tabs)

    By default, Threat Stack sorts alerts by severity, type, active, or dismissed.

    Search field

    Alert trends over time (histogram)

    Alert information table and filter rule and ruleset details

    Reviewing Alerts

    We recommend using the Alert Trends histogram to navigate to alert spikes. This can help you access alert details quickly and efficiently review additional information.

    In the Alert Trends, you can select a desired time frame along the histogram to view the behaviors that caused the alerts. As you move the vertical markers to your desired timeline, the information in the right view pane, such as "Filter by Rule" and "Filter by Tags", changes to display relevant content related to the behaviors in the body of the alerts. The filter pane also shows the specific behaviors and events to help you determine whether any further analysis and action is required.

    Alert Details Information

    When reviewing alerts in list view, the following information is displayed:

    Severity level of the alert

    Title of the alert

    Date and time of the alert

    Alert suppression icon

    Select an alert to view detailed event information.

    Additional information about the events contributing to the alert are displayed, such as:

    The date and time of the first event that triggered the alert (The default timestamp).

    The timestamp of the last event that contributed to the alert.

    The last five contributing events related to the alert.

    Clicking the View Contributing Events link displays the last five contributing events in chronological order starting with the most recent event.

    4. Resolve an Alert

    On the Alerts page, you can view, suppress, and dismiss alerts. The "Dismiss Alert" functionality enables you to acknowledge particular behaviors and track the dismissed alerts for compliance.

    Dismissing an Alert vs Suppressing an Alert

    When you dismiss an alert, it removes it from view. If the behavior happens again the alert will re-appear.

    Suppressing an alert whitelists the behavior. Hence, you will not see the alert again. If you suppress an alert, it indicates youdon'twant to receive alerts about the behavior. See the article for more information.

    Dismissing an Alert

    Dismissing an alert indicates you have reviewed and acknowledged a particular behavior, or a set of behaviors. From a compliance perspective, a record of dismissed alerts shows an auditor you reviewed and acknowledged particular behaviors.

    Note

    Youdon'tdismiss at the alert level. You dismiss alerts at the rule level.

    To dismiss an alert or multiple alerts, navigate to the Alerts page.

    On the Alert Trends histogram, navigate to an alert spike using the vertical markers.

    After selecting an alert timeline, review the Filter by Rule pane for the rule filter that triggered the alert behavior.

    Select a specific alertto review the contributing events and determine why the behavior happened.

    Select the checkbox for the alert. The Dismiss pane displays in the right view.

    Select your Dismiss Alerts Reason and click the Dismiss [#] Alert button.

    You can review dismissed alerts in the Dismissed Alerts tab.

    View Article
  • A Windows host rule will alert you to user activity on your Windows system. You can add a host rule in the Threat Stack Cloud Security Platform (CSP).

    Note

    If you are looking to create a Linux host rule, please review the Creating a Linux Host Rule article.

    Navigate to the Rules tab and select a ruleset from the list.

    Click the + New Rule button.

    Automatically Integrate with AWS using CloudFormation

    Note

    You can create a rule in any ruleset to suit your organization's needs. In this example, the new rule is added to the Base Rule Set.

    The Add Host Rule dialog displays.

    Select Windows Host Rule from the list and click Next: Details to proceed.

    The Add Windows Host Rule dialog displays. You will be able to specify the rule details.

    Severity of alerts: There are three levels of behaviors to indicate the severity of an alert.

    Severity 1 alerts are the highest elevation of behaviors.

    Severity 2 alerts are the second highest elevation of behaviors.

    Severity 3 alerts are the third highest elevation of behaviors.

    Rule Name (Required): It indicates the name of the ruleset.

    Alert Title (Required): It indicates the name and substitutions (dynamic content) which add context to the alert.

    Alert Description: It indicates a brief summary of the alert.

    Aggregate Fields: It helps define the uniqueness of an alert. Please review the Rule Aggregation article for additional information about aggregate options.

    Trigger an alert if an event matching this rule occurs at least: It indicates the frequency for generating an alert. You can specify how often to display an alert within a certain time frame. For additional information, please review the Life Cycle of an Alert article.

    After making your selection, click Next: Filter.

    The Windows Host Rule Filter pane displays.

    Tip

    If you have integrated your Amazon Web Services (AWS) account into Threat Stack, the Deployment Options pane appears next. You can specify AWS EC2 tags for this rule and automatically assign the rule to all associated hosts. For additional information, please review the AWS EC2 Tags article.

    However, if you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in to enable this integration.

    After specifying a rule filter, click Create Rule.

    The rule creates and displays on the Rules page.

    View Article
  • Amazon Web Services (AWS) allows users to assign tags to their AWS resources. Tags are simple labels that consist of a customer-defined key and value. Examples include role:webserver or env:production.

    Once you integrate Threat Stack and AWS, the Threat Stack Cloud Security Platform automatically ingests EC2 tag information. You can then use tags to apply specific rules to servers. This simplifies and speeds up tuning and deployment, and improves relevancy of alerts.

    Prerequisites

    Access to the Threat Stack console.

    An enabled Threat Stack AWS EC2 Agent correlation. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    View AWS EC2 Tags

    Note

    AWS EC2 tags are not available for CloudTrail or Configuration Audit rules.

    To see which tags are applied to a rule, in the Create Rule or Edit Rule dialog, click the Deployment interface.

    Tip

    If you do not see the Deployment interface, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    View tags from rules:

    FAQ: Do I have to use AWS EC2 tags?

    View tags from alerts:

    Add AWS EC2 Tags

    Note

    AWS EC2 tags are not available for CloudTrail or Configuration Audit rules.

    Add AWS EC2 tags when you create a rule

    Log into Threat Stack.

    Click Rules. In the right view pane, the Rules page displays.

    Click the Rule Set to which to add the rule.

    Click the + New Rule button. In the right display pane the + Add Rule page displays.

    Do one of the following:

    Select a type for your new rule (Host Rule, File Integrity Rule, CloudTrail Rule, Threat Intelligence Rule orWindows Host Rule).

    Click the Next: Details button. The Add [Rule Type] Rule page displays.

    In the Rule Name (required) field, type the name of the rule. Threat Stack recommends using the rules purpose as a title.

    In the Alert Title (required) field, type the title of alerts tied to this rule. Threat Stack recommends using the rule name as the alert title.

    Click the Next: Filter button. The + Add Rule page displays the 3. [Rule Type] Filter Rule page.

    In the Apply the new rule to events that match this filter field, type the criteria by which the rule singles out events for further inspection by Threat Stack.

    Click the Next: Deployment button. The + Add Rule page displays the 4. Deployment Options page.

    Tip

    If you do not see the Deployment tab, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    Click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.

    Tip

    This field is pre-populated with all tags available on your AWS resources.

    Click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu select one or more AWS EC2 tags to ignore when applying the rule.

    Tip

    This field is pre-populated with all tags available on your AWS resources.

    Click the Apply Tags button.

    The rule creates and the tag(s) apply to the rule. Within 10 minutes Threat Stack will process the rule and the tag(s), and apply the rule to any of your AWS hosts with a matching tag.

    Clone an existing rule.

    Select the Clone Existing Rule type button.

    Click the Next: Details button. The Clone Existing Rules page displays.

    Select the existing rule(s) to clone.

    Click the Clone [no.] Rule button. The new rule creates. In the right view pane, the rule details display.

    In the Deployment section of the rule, click in the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.

    Tip

    If you do not see the Deployment section, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    This field is pre-populated with all tags available on your AWS resources.

    Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.

    Click the Apply Tags button.

    The rule creates and the tag(s) apply to the rule. Within 10 minutes Threat Stack will process the rule and the tag(s), and apply the rule to any of your AWS hosts with a matching tag.

    Add AWS EC2 tags to an existing rule

    Log into Threat Stack.

    Click Rules. In the right view pane, the Rules page displays.

    Select the rule to which to apply AWS EC2 tags. In the right view pane, the rule displays.

    In the Deployment section, click the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.

    Tip

    If you do not see the Deployment section, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    This field is pre-populated with all tags available on your AWS resources.

    Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.

    Click the Apply Tags button.

    The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.

    Add AWS EC2 tags to a rule from an alert

    Log into Threat Stack.

    Click Alerts. In the right view pane, alerts display.

    Select an alert for the rule to which you want to apply an AWS EC2 tag.

    Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.

    Click the Deployment tab. The Deployment page displays.

    Tip

    If you do not see the Deployment tab, then your Threat Stack AWS EC2 Agent correlation is not enabled. Follow the steps in Automatically Integrate with AWS using CloudFormation to enable this integration.

    Click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.

    Tip

    This field is pre-populated with all tags available on your AWS resources.

    Optionally, click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu, select one or more AWS EC2 tags to ignore when applying this rule.

    Click the Apply Tags button.

    The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.

    Edit AWS EC2 Tags

    You can change the AWS EC2 tags applied to rules at any time.

    Edit AWS EC2 tags applied to a rule

    Log into Threat Stack.

    Click Rules. In the right view pane, the Rules page displays.

    Select the rule to which to edit AWS EC2 tag(s). In the right view pane, the rule displays.

    In the Deployment section, click the Applied tags field, and from the drop-down menu select one or more AWS EC2 tags to apply to the rule.

    Tip

    This field is pre-populated with all tags available on your AWS resources.

    Click in the Exclude all hosts with any of the following tags from this rule field, and select one or more AWS EC2 tags to ignore when applying the rule.

    Click the Apply Tags button.

    The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.

    Edit AWS EC2 tags applied to a rule from an alert

    Log into Threat Stack.

    Click Alerts. In the right view pane, alerts display.

    Select an alert for the rule to which you want to edit AWS EC2 tag(s).

    Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.

    Click the Deployment tab. The Deployment page displays.

    Click the Applied tags field, and select one or more AWS EC2 tags to apply to the rule.

    Tip

    This field is pre-populated with all tags available on your AWS resources.

    Optionally, click the Exclude all hosts with any of the following tags from this rule field, and from the drop-down menu, select one or more AWS EC2 tags to ignore when applying this rule.

    Click the Apply Tags button.

    The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.

    Delete AWS EC2 Tags

    You can delete an AWS EC2 tag associated with a rule at any time.

    Note

    You cannot remove a tag from your AWS resources by deleting it from a rule in Threat Stack.

    Delete AWS EC2 tags applied to a rule

    Log into Threat Stack.

    Click Rules. In the right view pane, the Rules page displays.

    Select the rule from which to delete AWS EC2 tag(s). In the right view pane, the rule displays.

    In the Deployment section, in the Applied tags field, click the X button next to the tag(s) to delete.

    The tags delete from the rule.

    Optionally, in the Exclude all hosts with any of the following tags from this rule field, click the X button next to the tag(s) to delete. The tags delete from the rule.

    Click the Apply Tags button. The tags apply to the rule. Within 10 minutes Threat Stack will process the tag(s), and apply the rule to any of your AWS hosts with a matching tag.

    Delete AWS EC2 tags applied to a rule from an alert

    Log into Threat Stack.

    Click Alerts. In the right view pane, alerts display.

    Select an alert for the rule from which you want to delete AWS EC2 tag(s).

    Click the Edit Rule link. The Edit [Rule Type] Rule dialog displays.

    Click the Deployment tab. The Deployment page displays.

    In the Applied tags field, click the X button next to the tag(s) to delete. The tags delete from the rule.

    Optionally, in the Exclude all hosts with any of the following tags from this rule field, click the X button next to the tag(s) to delete. The tags delete from the rule.

    Click the Apply Tags button. The tags apply to the rule. Within 10 minutes Threat Stack will process the tags, and apply the rule to any of your AWS hosts with a matching tag.

    Related FAQs

    FAQ: How are AWS EC2 tags ingested by Threat Stack?

    FAQ: How does Threat Stack apply AWS EC2 tags?

    FAQ: How long does it take for new / edited / deleted AWS EC2 tags to show up?

    FAQ:Whydon'tAWS EC2 tags to show up for CloudTrail?

    FAQ: Whydon'tAWS EC2 tags show up for Configuration Audit?

    View Article
  • Organizing, viewing and curating alerts is a vital piece of the workflow in managing security of cloud environments. Based on customer feedback and for an improved overall experience, we re-designed the Alerts page to address the following issues:

    Significantly faster page loading, even with thousands of open alerts.

    Quickly search through alerts - for example, show me all alerts that have a particular user name or ones with a specific command or argument(s).

    Create customized alert views - for example, every time I log into my account I want to see alerts from my database servers.

    Note

    The default view of the Alert Trends histogram is now seven days. Double-clicking the histogram will revert to displaying a date range covering one year.

    How do I Suppress an Alert?

    Important

    If a rule that triggered an alert is deleted, a generic icon () displays on the Alerts page instead of the icon associated with the triggered rule.

    Features

    Tabs as focus areas: We narrowed in on the well-known concept of browser tabs as focus areas, with in-built default tabs and the ability for customers to create and save their own tabs. Each tab can be customized to match the originating rulesets and/or originating servers (EC2 tags).

    Live alert loading: The Alerts page will display alerts as they come in. It will not delay the loading of alerts coming into the Threat Stack Cloud Security Platform (CSP).

    Search on alert titles: All tabs have a "Filter by Title" search field. Results appear as the users type in the words in the search bar.

    Alert Tabs

    The following alert tabs are displayed on the Alerts page:

    Sev 1: It displays a histogram and a list for the highest level of alerts.

    Sev 2: It displays a histogram and a list for the second highest level of alerts.

    Sev 3: It displays a histogram and a list for the third highest level of alerts.

    CloudTrail: It displays a histogram and a list of alerts related to CloudTrail events in your Amazon Web Services (AWS) environment. For more information, please review the Get Started with CloudTrail Alerting article.

    Note

    To view CloudTrail alerts, ensure you have enabled integration of your AWS environment within the Threat Stack CSP. For more information, please review the AWS Integrations Overview article.

    All Active Alerts: It displays a histogram and a list of all active alerts.

    Dismissed Alerts: It display a histogram and a list of dismissed alerts.

    When you dismiss an alert, it removes it from view. If the behavior happens again the alert will re-appear.

    Adding a New Alert Tab

    You can customize the Alerts page by adding a new tab.

    Click the Add New Tab button

    The + Add New Tab dialog displays.

    After specifying a tab name and description, click the Add New Tab button.

    The newly added tab displays with its name and description.

    Viewing a Hidden Alert Tab

    You can display hidden tabs on the Alert page.

    Click the Hidden Tabs button.

    The Select a Tab dialog displays.

    Search or select the tab name to display. In this example, DismissedAlerts was selected.

    The tab is now visible on the Alerts page. To revert to hiding the tab, click the closeicon (x) to remove it.

    Alert Filtering Options

    You can filter your alerts for troubleshooting or investigative purposes. There are various filter categories to choose from on the Alerts page.

    Select an alert tab.

    Click the expand / collapse button to display the filter dialog.

    Some of the filter options are as follows:

    Filter by Rule

    Filter by Tags

    Filter by Ruleset

    Filter By Severity

    Note

    This filter option does not appear for Severity 1 (Sev 1), Severity 2 (Sev 2) and Severity 3 (Sev 3) alerts.

    After making your selection, your filtered alerts are displayed.

    Note

    You can select multiple filter options from different categories. For example, you can select a rule from the Filter by Rule pane and a ruleset from the Filter by Ruleset pane.

    To remove your newly added filters, click the Clear all filters button.

    Related Articles

    Alert Feature Overview

    Alert Trends Functionality

    Life Cycle of an Alert

    View Article
  • Overview

    Threat Stack designed the Alert Trends histogram feature to help you understand trends of abnormal behaviors. This feature can help you accelerate the time it takes to manage alerts inside of Threat Stack.

    How do I Suppress an Alert?

    Important

    The default view of the Alert Trends histogram is seven days. Double click the histogram to display a date range covering one year.

    The Feature

    The Alerts page shows the Alert Trends histogram organized over time by the number and severity of alerts found on a daily basis. This can help you better track the abnormal spikes of alerts and review the behaviors that caused the events.

    In the Alert Trends histogram, you can select a desired time frame along the histogram to view the behaviors that caused the alerts. As you move the vertical markers to your desired timeline, the information in the right view pane, such as "Filter by Rule" and "Filter by Tags", changes to display relevant content related to the behaviors in the body of the alerts. The filter pane also shows the specific behaviors and events to help you determine whether any further analysis and action is required.

    Daily Use and Workflow

    This section reviews the optimal workflow to help you manage (review, acknowledge, dismiss, or suppress) your alerts quickly using the Alert Trends view and the Alerts filter.

    Use Case: Review and Dismiss an Alert

    In this scenario, you log into Threat Stack and navigate to the Alerts page. Click List View to display the latest alerts in chronological order, with the most recent alerts appearing first.

    You review the Alert Trends histogram to confirm the following:

    The date with the most alerts

    The trend that caused the alerts since your last login

    Important

    Requests to dismiss alerts are queued and do not occur in real time. Hence, refreshing the Alerts page immediately after dismissing an alert can cause the page to incorrectly display the alert count.

    In this example, the largest set of alerts was generated between August 15th and August 19th.

    Move the vertical markers along the histogram to the date range with the most number of alerts.

    All alerts generated during that timeframe are displayed. Ensure List View is selected for a detailed list of the alerts.

    Review the Filter by Rule pane to determine the rule filter that caught the alert behavior.

    In this example, some of the rule filters were:

    CloudTrail Activity (Access Denied) for {{eventName}} by {{user}}

    CloudTrail: KMS Read Event: {{user}} {{eventName}} in account {{accountId}}

    Select a specific alert to review the contributing events and determine why the behavior happened.

    You can select the alerts associated with the behavior and then:

    Acknowledge and dismiss the behavior (see the Life Cycle of an Alert article for resolving an alert)

    Suppress the behavior (see the How do I Suppress an Alert? article)

    For this example, we dismiss the alert by clicking the Dismiss 1 Alert button.

    Repeat this process as necessary. We recommend reviewing other alert behavior spikes and use the dismiss or suppress functionality as needed.

    Additional Alert articles include:

    Alert Feature Overview

    Life Cycle of an Alert

    View Article
  • Introduction

    Threat Stack is a behavior based anomaly detection platform, based on telemetry delivered into the platform from various sources, including your host and your infrastructure.

    What is an Alert?

    Alerts are behavior anomalies elevated from the stream of raw telemetry by rule filters. Alerts contain two main components:

    The alert title

    The contributing events

    Term

    Definition

    Contributing Events

    The raw telemetry that caused the anomaly to happen.

    Alert Title

    The name and substitutions (dynamic content) that adds context to the alert.

    The substitution fields should match the aggregation fields selected for the alert. The aggregation fields define the uniqueness of the alerts. See the Life Cycle of an Alert article for additional information on aggregations.

    Alert Trends Functionality

    Where Do I Find Alerts in the Threat Stack Application?

    In the left navigation bar, select the Alerts tab. The Alerts page displays the following information:

    Alert Trends over time in the form of a histogram

    Alerts sorted by severity, type, active or dismissed

    Alert information table including filter rule and ruleset details

    On the Alerts page you have the option to:

    Select an alert to review its alert details

    Suppress an alert

    Dismiss an alert (if you dismiss an alert it displays in the Dismissed Alerts tab)

    Important

    If a rule that triggered an alert is deleted, a generic icon () displays on the Alerts page instead of the icon associated with the triggered rule.

    Why Would an Alert Trigger?

    Alerts trigger when Threat Stack detects a behavior anomaly deemed inappropriate based on the rules you enabled or created. Rules require a filter to match behaviors against raw telemetry.

    Term

    Definition

    Telemetry

    Events and behavior anomalies.

    Rules

    Behaviors that you want to catch from the raw telemetry stream.

    Rule Filter Example

    Behavior to Catch

    Rule Filter

    Privilege escalations

    command =sudo

    User access

    Event_type =login"

    If a rule displays alerts for behavior you consider baseline or normal, you can create a suppression filter to have it no longer report that behavior. The content should match the aggregation fields selected for the alert. The aggregation fields define the uniqueness of the alerts. See the How do I Suppress an Alert? article.

    Threat Stack includes three levels of elevation of behaviors to indicate the severity of the alert:

    Severity 1 (Sev 1): It is the highest elevation of behaviors.

    Recommended for behaviors and scenarios that should wake you up in the middle of the night. Only used for behavior anomalies where an action and remediation runbook exists.

    Severity 2 (Sev 2): It is the second highest elevation of behaviors.

    Recommended for behaviors you want to monitor and review with stakeholders to improve over time.

    Severity 3 (Sev 3): It is the third highest elevation of behaviors. Sev 3 alerts are automatically dismissed after 30 days.

    Recommended for behaviors that companies log for compliance or forensics purposes.

    Additional Alert articles include:

    Life Cycle of an Alert

    How do I Suppress an Alert?

    View Article
  • Threat Stack provides a secure integration with your Amazon Web Services (AWS) account to monitor changes to your infrastructure through CloudTrail. For more information about setting up a CloudTail integration, please review the AWS Integrations Overview article.

    This article covers the following:

    CloudTrail rules best practices and examples

    CloudTrail alerts

    What is Threat Stack CloudTrail Monitoring?

    AWS CloudTrail monitoring is one way Threat Stack comprehensively monitors your infrastructure and workload. Using Threat Stacks CloudTrail integration, you can be alerted on changes to your instances, security groups, S3 buckets, and access keys. You can also determine whether any of these changes had adverse effects on your systems.

    If you have multiple AWS accounts, you can see across accounts to track risk in the Threat Stack Cloud Security Platform (CSP). With CloudTrail monitoring enabled, you can reduce the exposure window of an attack or an insider threat.

    How does Threat Stack Alert on Non-Compliant Changes to Your Infrastructure?

    Threat Stack has built-in rules (part of the CloudTrail Base Rule Set) that capture several AWS best practices, alerting users when non-compliant calls are made to their infrastructure.

    Let's review some examples below.

    Example 1: AWS account was compromised with the attacker compromising logs

    When an account is compromised, one of the first things the attackers would do is to stop logging the call and delete existing trails. The Cloud Trail Admin Activity ruleset monitors administrator activity, including updates to trails and creation of new trails.

    How do I Suppress an Alert?

    This rule was created with the "eventName" as the parameter for the rule filter. You can create any rule based on any "eventName" or "eventSource".

    Example 2: Users running instances in non-standard hidden regions incurring costs

    The ruleset in this example monitors and alerts you when an instance is launched into a non-standard region.

    This rule was created with the "eventName" and region combination as parameters for the rule filter.

    Example 3: Are security groups getting created or changed outside of your security policy?

    The ruleset in this example monitors and alerts you when a security group is changed.

    This rule was created with the following "eventName" parameter keys:

    AuthorizeSecurityGroupEgress

    AuthorizeSecurityGroupIngress

    CloudTrail Alerts

    CloudTrail alerts appear on the Alerts page.

    Clicking the CloudTrail tab will display a histogram and a list of all active CloudTrail alerts.

    Clicking the expand / collapse button will display the Filter dialog. For additional information about alert filtering options, please review the Alert View article.

    Clicking List View will display alerts by severity level.

    Select the image to enlarge it.

    Clicking an alert will display the alert preview pane along with the following information:

    The date and time of the API call

    The user name that made the API call

    The account associated with the API call

    Clicking the View Contributing Events link displays the last five contributing events that caused the alert.

    In this example, there was only one contributing event.

    Clicking the View/Edit Rule link displays an Edit CloudTrail Rule dialog, enabling you to view and update the following fields:

    The rule name

    The alert title

    Filter options

    Suppression settings

    You can choose to not get alerts on specific users or actions by adding a suppression. For additional information on suppressing alerts, please review article.

    View Article
  • This document can answer some frequently asked questions (FAQs) about the Threat Stack CloudTrail Monitoring feature. It can also provide some basic troubleshooting suggestions.

    Important

    Access to CloudTrail information will vary based on the Threat Stack Plan you purchased.

    Frequently Asked Questions

    How do I know if CloudTrail Monitoring works?

    When Threat Stack connects properly with CloudTrail, you can view events and alert details on either the Alerts or Events page.

    The example below shows a view of CloudTrail alerts.

    Alternatively, you can view CloudTrail events on the Events page by entering event_type = cloudtrail into the search field.

    Select the image to enlarge it.

    What if I don't see CloudTrail alert details on the Alerts page?

    If you don't see an alert, wait 10 minutes. If no alerts display after 10 minutes, you can test CloudTrail alerts by triggering an event. Event example: Log in to the console.

    If the event you trigger displays in CloudTrail but not in the Threat Stack Cloud Security Platform (CSP), please see the troubleshooting suggestions below.

    What does the clock icon (Status column on the Settings page in the CSP) mean?

    The clock ( CloudFormation template ) icon indicates Threat Stack's attempt to connect to Amazon Web Services (AWS). This connection can take upwards of 10 minutes. Navigate away from the Settings page and return after 10 minutes. You will see a green checkmark () icon or an error () icon indicating the success or failure of the connection attempt.

    What if I see a green checkmark () icon but I don't see CloudTrail events or alert details?

    If you experience this issue, it indicates Threat Stack can connect to your AWS account but cannot display data.

    Important

    Your feature plan will determine whether CloudTrail alert details are displayed on the Alerts page.

    Please review the following troubleshooting suggestions and best practices:

    Ensure no other application can read messages off this queue.

    If another application can acknowledge messages off the same queue, it will interfere with Threat Stack's ability to read the messages.

    Confirm the message ticker indicates 1 messages in the SQS Queue.

    Navigate to the SQS service in the AWS Console.

    Choose the appropriate queue.

    Review the Messages Available field.

    What if I can see one or more messages in the Message Available field?

    Confirm your Queue Name matches what you entered in Threat Stack.

    Navigate to the Settings page.

    Select the Integrations tab.

    In the AWS Accounts module, select the Edit ()icon.

    Within the Edit AWS Integration screen, confirm the SQS Source field displays the correct Queue Name.

    Within AWS, you can find your Queue Name in the SQS Service area within the AWS Console.

    Within Threat Stack, you can find the Queue Name on the Edit AWS Integration screen.

    Confirm the region selected in the Edit AWS Integration screen matches the region in the SQS ARN.

    Navigate to the Settings page.

    Select the Integrations tab.

    In the AWS Accounts module, select the Edit () icon.

    Within the Edit AWS Integration screen, verify the region in the Select Regions field.

    Within the AWS Console, open the Queue details and check the ARN or URL fields.

    Within Threat Stack, you can find the region on the Edit AWS Integration screen.

    In AWS, review the policy on the 3rd party cross-account IAM role to confirm Threat Stack has permission to read the queue.

    What if I can't see any (0) messages in the Message Available field?

    Note

    Best practice: Redo the integration using the .

    Please review the following troubleshooting suggestions:

    Confirm the queue subscribes to the proper SNS topic.

    Navigate to the SNS.

    Confirm that the SNS topic displays the SQS Queue as a subscription endpoint.

    Confirm CloudTrail delivers logs properly and sends notifications using the SNS topic.

    What if I see the error () icon?

    If you experience this issue, it indicates Threat Stack cannot connect to your AWS Account.

    Please review the following troubleshooting suggestions and best practices:

    Confirm the Role ARN entries match in Threat Stack and AWS.

    Navigate to the Settings page.

    Select the Integrations tab.

    In the AWS Accounts module, locate the ARN column and verify the Role ARN value.

    Within Threat Stack, you can find the Role ARN in the AWS Accounts module.

    Within AWS, locate the 3rd party cross-account and verify the Role ARN entry.

    Confirm the External ID entries match in Threat Stack and AWS.

    Navigate to the Settings page.

    Select the Integrations tab.

    In the AWS Accounts module, locate the External ID column and verify the External ID.

    Within Threat Stack, you can find the Role ARN in the AWS Accounts module.

    Within AWS, locate the 3rd party cross-account and verify the Role ARN entry.

    View Article
  • Threat Stacks Threat Intelligence feature correlates the outgoing and incoming IPs out of the host with the Threat Stack curated IP list from various sources.

    IP Source Lists

    We have both open source and commercial sources

    Partial open source list

    http://www.dshield.org/ipsascii.html

    http://www.dshield.org/block.txt

    Partial commercial source list

    Iblocklist: iblocklist.com/lists

    Configuration Steps

    The default threat intelligence rule that comes right off the box captures outgoing traffic (type=connect) and generates a severity 1 alert. The configuration involves three simple steps

    Enable the threat intelligence rule under rule sets (please contact support if you do not see the rule set)

    Tweak the rule for the right severities and filters (ex - you want to add capture incoming traffic as well and change severities on that)

    Associate the rule set with servers you want to see alerts on

    Customers can also create new custom rules by following the below steps.

    Create a New Threat Intelligence Rule

    Customers can create custom threat intelligence rules (click add new threat intelligence rule) based on the below filter keys.

    network event types (type = connect or type = accept)

    threatintel_source: The fields here are

    tscommercial

    threatintel_reason

    scanning host

    spamming host

    malicious host

    threatintel_type

    IP

    A custom filter might looks like

    type=connect and threatintel_reason=malicious host

    Please select aggregations for the alert title to work.

    An example is below.

    Result Types

    Similar to other features, threat intelligence features is manifested in two places - alerts and events.

    Events

    We generate an event of type threatintel (event_type="threatintel") when there is a IP match with any of the bad IP lists. The event has information on whether the connections is a inbound or outbound, the source of the threat intelligence and the reason. The user can search for any of the corresponding fields as the below examples illustrate.

    Alerts

    Alerts will be generated if there's a match and you would see them on the alerts screen. The text filtering for the alerts would the threat intelligence.

    Contributing Events

    After you click on the alert, you would see the contributing event, you would see the details related to the match - the source, the reason and the type.

    View Article
  • Example Commands and Alerts

    Testing your rules allows you to verify that your system is configured properly in Threat Stack.

    Threat Stack can monitor file:

    Creation

    Opening

    Modifying

    Closing

    Deleting

    How do I test the FIM rules?

    You can test FIM by performing the above actions (examples below) on files within monitored directories. If you need help understanding which directories Threat Stack monitors, refer to the Overview of File Integrity Monitoring article.

    Note

    This is a limited list of commands to give you an idea of ways to test FIM within Threat Stack.

    Command line

    Explanation

    Example Event Types

    vi [filename]

    Opens the file withthe vi text editor

    access, open, and close

    echo [enter text] > secret file

    Takes texts and add itto the end of a file.

    modify, close, write and open event

    wget

    Downloads a filefrom the internet.

    modify, open, close, and write event

    curl

    Downloads a filefrom the internet.

    modify, open, close, and write event

    scp outsidehost:/file secretfile

    Copies a file from an outside host to your system.

    open, modify, close, and write event

    scp secretfile outsidehost:/file

    Takes a file from your system and copies it toan outside host.

    open, access, and close event

    Example

    Running the vi command to trigger an event and alert.

    Choose a file that should be monitored within Threat Stack

    Navigate to that files directory

    Type vi [filename]

    Result: File opens in vi

    To exit vi enter :q

    Note

    FIM events can take up to a minute to display within the Threat Stack system.

    Where can I view my results?

    Go to the Alerts tab on the left hand side.

    Select the Sev 3 tab to display Severity 3 alerts.

    Result: You should see an alert for the event that you triggered.

    FIM Troubleshooting Guide

    What if Idon'tsee an alert for the event?

    Check out the or contact support.

    View Article
  • Threat Stack Agent & Event Stream Data Overview

    This article is designed to help you understand the extensive capabilities of the event stream data collected by the Threat Stack Agent. The examples in this article can help you understand how to better monitor and alert on a few common cloud security use cases.

    These are the fundamental ideas for how Threat Stack designed our security monitoring:

    Event Processing - the Threat Stack Agent collects events around system, process, and user actions and streams them to the backend application.

    Rule Based Identification - to isolate signal from noise, events are processed against system and user-defined Rule Sets to identify critical events of interest.

    Alert Notification - identified issues generate alerts which generate notifications.

    Alert Management - dismissing or suppressing alerts.

    Use Cases

    The Threat Stack Agents collects events around user activities, process, host and network events. Our application backend correlates the event stream data to provide a context for common security use cases.

    User Access Monitoring

    Use Case (1) Events of interest for any user and group modifications (Add/Remove/Modify) on production systems.

    How Do I Configure Network Access for the Agent?

    Use Case (2) Events for any user privilege escalations, a typical scenario is for customers to have an approved list of sudo users and wants alerting and log trail for any violations.

    Use Case (3) Detect unauthorized changes on production system. Only the configuration management agent (Chef, Puppet, Ansible, Salt) is authorized for deploys/file copy/install; track any user violations for change operations.

    Use Case (4) Generate detailed events and an audit trail for all users' TTY sessions for activity monitoring.

    Use Case (5) Monitoring for any privileged application user accounts usage.

    Use Case (6) Abnormal user login/access attempts (rate or login/brute forcing/password attacks).

    System Integrity Monitoring

    Use Case (1) An unauthorized system kernel module or package is loaded or initialized on production systems (indicators of rootkit, APT type malware).

    Use Case (2) Detect for deviations for any changes in authorized Ports/Services (Process binds/open).

    Use Case (3) Events for any new process connection states. Typically new ACCEPT/CONNECT, this indicates possible intrusion or command-and-control type of activities for unauthorized connectivity.

    Use Case (4) Track any unauthorized or abnormal process Start events by user or processes.

    Use Case (5) Audit trail activity for any critical file system changes/reads/transfers and permissions changes.

    File Integrity Monitoring

    Use Case (1) Monitoring critical credential file access/modifications for misuse/abuse typically indicates insider threat activities.

    Use Case (2) Monitor Critical system directories (/boot/, /lib, /usr/lib, /bin/, /sbin, /etc) for new executables or binary replacement/modification typical indicates intrusion or command-and-control activities.

    Use Case (3) Monitor unauthorized modifications to system and application configuration files (e.g: sshd.conf, ntp.conf, resolv.conf Apache, MySQL, etc).

    Use Case (4) Monitor for any data exfiltration type of activities on critical identified files (OPEN, COPY, TRANSFER) - Insider threat scenarios typically related to stolen credential files, SSH Keys, certificates.

    Network Activity Monitoring

    Use Case (1) Monitoring for any critical system services changes (NTP, DNS, Syslog) daemon re-configuration/port/destination or source changes.

    Use Case (2) Monitoring for any System Application Service changes (Apache, DB Server Binds, Proxy, Application Services).

    Use Case (3) Monitoring for insecure protocol usage for System access (Telnet, FTP).

    As an example, enter dst_port = 23 or dst_port = 21 in the event search field.

    Additional Information

    How Does Threat Stack Collect Data and What Data is Collected?

    View Article
  • Introduction

    This page includes frequently asked questions Threat Stack has received about File Integrity Monitoring (FIM) and the File Transfer Protocol (FTP).

    How Do I Use FIM To Monitor a FTP?

    You can track a FTP services exfiltrating data away from your system using the Threat Stack FIM monitoring service.

    Create a FIM rule to monitor a sensitive file or directory. After you create a FIM rule, if a FTP service copies a file to a remote system an event triggers in Threat Stack and you receive an alert stating the file was opened by the service.

    How Do I Whitelist a Particular User in FTP?

    To whitelist a particular user, you have to add a suppression to the rule they currently trigger.

    Note

    Threat Stack stores rules on the host and not the backend. This means rules can take a few minutes to update. Additionally, a rule suppression is not recursive.

    On the Alerts page, click the Suppressionbutton.

    How to Monitor other Folders for Invalid Users

    On the Add New Host Rule Suppression dialog, specify the user to suppress.

    Click the Add New Suppression button.

    You added a suppression to a ruleset. Going forward, Skyler will not trigger an alert related to this rule.

    For more information on Suppressions, see the How do I Suppress Alerts? article.

    How Do I Monitor Other Folders For Invalid Users?

    To monitor other folders for invalid users:

    Create a rule to monitor changes in all home directories.

    Create suppressions for each user for their own home directory.

    See the article for the full instruction set.

    View Article
  • Raw events All events ingested by Threat Stack. Threat Stack retains raw events according to your companys retention policy a period of one or three days.

    Contributing events Events that trigger alerts. Threat Stack retains contributing events for one calendar year from the date of the triggered alert.

    View Article
  • Issue

    I suppress an event from the Alerts page. When I click the Test Filter button, Idon'tsee any events that match the suppression.

    Root Causes

    There are two possible causes for this issue:

    The event that contributed to the alert falls outside of the retention period.

    The Test Filter button connects to the raw events stream, not the contributing events stream. More information on the differences between raw and contributing events here. As a result, Threat Stack only returns potential suppressions that match raw events that fall within your companys event retention policy (one or three days). Contributing events, which Threat Stack retains for one full calendar year from the date of the triggered alert, will not display in the potential suppression results and, if you apply the suppression rule, will not retroactively suppress.

    The data in the raw event search is different than the data in the alert search.

    The Test Filter button connects to the raw events stream. The raw event search contains augmented data. However, the alert search contains raw data. If you click the Test Filter button on the Alerts page, then Threat Stack is using the raw event search to return potential suppression results. Since the raw event search includes augmented data, it may not return potential suppressions that match raw alert data.

    View Article
  • Threat Stack user accounts lock out if the user types their password incorrectly too many times. If you are a Threat Stack organization owner, then you receive an email notifying you that a users account is locked out. You sign into the Threat Stack Cloud Security Platform (CSP) to unlock the account.

    Log into Threat Stack.

    In the left navigation pane, click the Settings tab. The Settings page displays.

    Click the Users tab. The Users page displays.

    In the row for the locked user account, in the Options column, click the Unlock button.

    A notification message displays.

    Click the Yes, Unlock Account button. The user account unlocks and the Unlock button no longer displays in the Options column. The user receives an email notifying them that their account is unlocked.

    View Article

Curious about Threat Stack?

Anonymously Ask Threat Stack Any Question

Ask Anonymous Question

×
Rate your company