Wiz Rule Change


Description

This rule detects creations, updates and deletions of Wiz rules.

Query · python

from panther_wiz_helpers import wiz_actor, wiz_alert_context, wiz_success

SUSPICIOUS_ACTIONS = [
    "DeleteAutomationRule",
    "UpdateAutomationRule",
    "DeleteCloudEventRule",
    "UpdateCloudEventRule",
    "DeleteCloudConfigurationRule",
    "UpdateCloudConfigurationRule",
    "DeleteHostConfigurationRule",
    "UpdateHostConfigurationRule",
    "CreateIgnoreRule",
    "DeleteIgnoreRule",  # we have no sample log for such event, but I suppose there should be one
    "UpdateIgnoreRule",
    "CreateMalwareExclusion",
    "UpdateMalwareExclusion",
]


def rule(event):
    if not wiz_success(event):
        return False
    return event.get("action", "ACTION_NOT_FOUND") in SUSPICIOUS_ACTIONS


def title(event):
    actor = wiz_actor(event)

    return (
        f"[Wiz]: [{event.get('action', 'ACTION_NOT_FOUND')}] action "
        f"performed by {actor.get('type')} [{actor.get('name')}]"
    )


def dedup(event):
    return event.get("id")


def alert_context(event):
    return wiz_alert_context(event)


def severity(event):
    action = event.get("action", "ACTION_NOT_FOUND")
    if "Delete" in action:
        return "High"
    if "Create" in action:
        return "Low"
    return "Default"

Analyst notes

Verify that this change was planned. If not, revert the change and ensure this doesn't happen again. If needed, review the privileges of existing accounts.

Raw source Wiz Rule Change · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
RuleID: Wiz.Rule.Change
Description: This rule detects creations, updates and deletions of Wiz rules.
DisplayName: Wiz Rule Change
Runbook: Verify that this change was planned. If not, revert the change and ensure this doesn't happen again. If needed, review the privileges of existing accounts.
Reference: https://www.wiz.io/blog/custom-runtime-rules-and-response-policies
Enabled: true
Filename: wiz_rule_change.py
Severity: Medium
Reports:
  MITRE ATT&CK:
    - TA0005:T1562.001  # Impair Defenses: Disable or Modify Tools
LogTypes:
  - Wiz.Audit
DedupPeriodMinutes: 60
Threshold: 1
Tests:
  - Name: DeleteCloudConfigurationRule
    ExpectedResult: true
    Log:
      {
        "action": "DeleteCloudConfigurationRule",
        "actionparameters": {
          "input": {
            "id": "12345-3fd7-4063-8e06-12345"
          },
          "selection": [
            "__typename",
            "_stub"
          ]
        },
        "id": "12345-0301-491d-9fe6-12345",
        "log_type": "auditLogEntries",
        "requestid": "12345-c18f-4ce0-9288-12345",
        "serviceaccount": null,
        "sourceip": "8.8.8.8",
        "status": "SUCCESS",
        "timestamp": "2024-03-24 10:58:31.347",
        "user": {
          "id": "testy@company.com",
          "name": "testy@company.com"
        },
        "useragent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
      }
  - Name: CreateUser
    ExpectedResult: false
    Log:
      {
        "id": "220d23be-f07c-4d97-b4a6-87ad04eddb14",
        "action": "CreateUser",
        "requestId": "0d9521b2-c3f8-4a73-bf7c-20257788752e",
        "status": "SUCCESS",
        "timestamp": "2024-07-29T09:40:15.66643Z",
        "actionParameters": {
          "input": {
            "assignedProjectIds": null,
            "email": "testy@company.com",
            "expiresAt": null,
            "name": "Test User",
            "role": "GLOBAL_ADMIN"
          },
          "selection": [
            "__typename",
            {
              "user": [
                "__typename",
                "id"
              ]
            }
          ]
        },
        "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36",
        "sourceIP": "8.8.8.8",
        "serviceAccount": null,
        "user": {
          "id": "someuser@company.com",
          "name": "someuser@company.com"
        }
      }
  - Name: DeleteCloudConfigurationRule - Fail
    ExpectedResult: false
    Log:
      {
        "action": "DeleteCloudConfigurationRule",
        "id": "12345-0301-491d-9fe6-12345",
        "log_type": "auditLogEntries",
        "requestid": "12345-c18f-4ce0-9288-12345",
        "serviceaccount": null,
        "sourceip": "8.8.8.8",
        "status": "FAILED",
        "timestamp": "2024-03-24 10:58:31.347",
        "user": {
          "id": "testy@company.com",
          "name": "testy@company.com"
        },
        "useragent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
      }


# ------ paired body: wiz_rule_change.py ------

from panther_wiz_helpers import wiz_actor, wiz_alert_context, wiz_success

SUSPICIOUS_ACTIONS = [
    "DeleteAutomationRule",
    "UpdateAutomationRule",
    "DeleteCloudEventRule",
    "UpdateCloudEventRule",
    "DeleteCloudConfigurationRule",
    "UpdateCloudConfigurationRule",
    "DeleteHostConfigurationRule",
    "UpdateHostConfigurationRule",
    "CreateIgnoreRule",
    "DeleteIgnoreRule",  # we have no sample log for such event, but I suppose there should be one
    "UpdateIgnoreRule",
    "CreateMalwareExclusion",
    "UpdateMalwareExclusion",
]


def rule(event):
    if not wiz_success(event):
        return False
    return event.get("action", "ACTION_NOT_FOUND") in SUSPICIOUS_ACTIONS


def title(event):
    actor = wiz_actor(event)

    return (
        f"[Wiz]: [{event.get('action', 'ACTION_NOT_FOUND')}] action "
        f"performed by {actor.get('type')} [{actor.get('name')}]"
    )


def dedup(event):
    return event.get("id")


def alert_context(event):
    return wiz_alert_context(event)


def severity(event):
    action = event.get("action", "ACTION_NOT_FOUND")
    if "Delete" in action:
        return "High"
    if "Create" in action:
        return "Low"
    return "Default"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.