Tailscale HTTPS Disabled


Description

A Tailscale User disabled HTTPS settings in your organization's tenant.

Query · python

from panther_tailscale_helpers import is_tailscale_admin_console_event, tailscale_alert_context


def rule(event):

    action = event.deep_get("event", "action", default="<NO_ACTION_FOUND>")
    target_property = event.deep_get(
        "event", "target", "property", default="<NO_TARGET_PROPERTY_FOUND>"
    )
    return all(
        [
            action == "DISABLE",
            target_property == "HTTPS",
            is_tailscale_admin_console_event(event),
        ]
    )


def title(event):
    user = event.deep_get("event", "actor", "loginName", default="<NO_USER_FOUND>")
    target_id = event.deep_get("event", "target", "id", default="<NO_TARGET_ID_FOUND>")
    return (
        f"Tailscale user [{user}] disabled HTTPS for "
        f"[{target_id}] in your organization’s tenant."
    )


def alert_context(event):
    return tailscale_alert_context(event)

Analyst notes

Assess if this was done by the user for a valid business reason. Be vigilant to re-enable this setting as it's in the best security interest for your organization's security posture.

Raw source Tailscale HTTPS Disabled · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Description: A Tailscale User disabled HTTPS settings in your organization's tenant.
DisplayName: "Tailscale HTTPS Disabled"
Enabled: true
Filename: tailscale_https_disabled.py
Runbook: Assess if this was done by the user for a valid business reason. Be vigilant to re-enable this setting as it's in the best security interest for your organization's security posture.
Reference: https://tailscale.com/kb/1153/enabling-https/#disable-https
Severity: High
Tests:
  - ExpectedResult: true
    Log:
      {
        "event":
          {
            "action": "DISABLE",
            "actor":
              {
                "displayName": "Homer Simpson",
                "id": "uodc9f3CNTRL",
                "loginName": "homer.simpson@yourcompany.io",
                "type": "USER",
              },
            "eventGroupID": "1770eb26fb58fbf67fd8fbfcc2056e66",
            "origin": "ADMIN_CONSOLE",
            "target":
              {
                "id": "yoururl.com",
                "name": "yoururl.com",
                "property": "HTTPS",
                "type": "TAILNET",
              },
          },
        "fields": { "recorded": "2023-07-19 16:10:48.385283827" },
        "p_any_actor_ids": ["uodc9f3CNTRL"],
        "p_any_emails": ["homer.simpson@yourcompany.io"],
        "p_any_usernames": ["andrea.youwakim"],
        "p_event_time": "2023-07-19 16:10:48.172000",
        "p_log_type": "Tailscale.Audit",
        "p_parse_time": "2023-07-19 16:13:56.849092",
        "p_row_id": "5e197fb53834e39eeab7feb9198d04",
        "p_schema_version": 0,
        "p_source_id": "5d65e24a-7ebb-403b-803c-51396e03d201",
        "p_source_label": "Tailscale Audit and Network Logs",
        "time": "2023-07-19 16:10:48.172000000",
      }
    Name: HTTPS Disabled
  - ExpectedResult: false
    Log:
      {
        "event":
          {
            "action": "CREATE",
            "actor":
              {
                "displayName": "Homer Simpson",
                "id": "uodc9f3CNTRL",
                "loginName": "homer.simpson@yourcompany.io",
                "type": "USER",
              },
            "eventGroupID": "9f880e02981e341447958344b7b4071f",
            "new": {},
            "origin": "ADMIN_CONSOLE",
            "target":
              { "id": "k6r3fm3CNTRL", "name": "API key", "type": "API_KEY" },
          },
        "fields": { "recorded": "2023-07-19 16:11:41.778839718" },
        "p_any_actor_ids": ["uodc9f3CNTRL"],
        "p_any_emails": ["homer.simpson@yourcompany.io"],
        "p_any_usernames": ["homersimpson"],
        "p_event_time": "2023-07-19 16:11:41.601000",
        "p_log_type": "Tailscale.Audit",
        "p_parse_time": "2023-07-19 16:14:56.865276",
        "p_row_id": "02eaf97ec9caaaabff8882ba19ad1d",
        "p_schema_version": 0,
        "p_source_id": "5d65e24a-7ebb-403b-803c-51396e03d201",
        "p_source_label": "Tailscale Audit and Network Logs",
        "time": "2023-07-19 16:11:41.601000000",
      }
    Name: Other Event
DedupPeriodMinutes: 60
LogTypes:
  - Tailscale.Audit
RuleID: "Tailscale.HTTPS.Disabled"
Threshold: 1


# ------ paired body: tailscale_https_disabled.py ------

from panther_tailscale_helpers import is_tailscale_admin_console_event, tailscale_alert_context


def rule(event):

    action = event.deep_get("event", "action", default="<NO_ACTION_FOUND>")
    target_property = event.deep_get(
        "event", "target", "property", default="<NO_TARGET_PROPERTY_FOUND>"
    )
    return all(
        [
            action == "DISABLE",
            target_property == "HTTPS",
            is_tailscale_admin_console_event(event),
        ]
    )


def title(event):
    user = event.deep_get("event", "actor", "loginName", default="<NO_USER_FOUND>")
    target_id = event.deep_get("event", "target", "id", default="<NO_TARGET_ID_FOUND>")
    return (
        f"Tailscale user [{user}] disabled HTTPS for "
        f"[{target_id}] in your organization’s tenant."
    )


def alert_context(event):
    return tailscale_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.