Skip to content

T1621 PingID: add UPN and multiple-reset regression fixture - #1230

Open
sbaker-gre wants to merge 1 commit into
splunk:masterfrom
sbaker-gre:pingid-credential-reset-upn-fixture
Open

sbaker-gre wants to merge 1 commit into
splunk:masterfrom
sbaker-gre:pingid-credential-reset-upn-fixture

Conversation

@sbaker-gre

Copy link
Copy Markdown

Adds regression data for PingID New MFA Method After Credential Reset.

The existing pingid.log / windows_pw_reset.log pair uses the bare name victim_user on
both sides. That hides two problems in the detection: PingID reports the IdP username
(typically a UPN), while Windows 4723/4724 carry the bare account name; and the join keeps
only one password event per user.

New files in datasets/attack_techniques/T1621/pingid/, dated 2023-10-16, synthetic:

  • pingid_upn_multi_reset.log: 5 PingID device pairings (_json, source=PINGID)
  • windows_pw_reset_upn_multi_reset.log: 6 Security 4723/4724 events (XmlWinEventLog)
Case Setup Expected
A victim_user2@attack_range.lan pairs 10 and 5 minutes after two resets 1 finding, nearest reset
B bare victim_user3: one reset after the pairing, one 10 minutes before 1 finding
C victim_user4@attack_range.lan: only reset is 90 minutes earlier none
D victim_user5@attack_range.lan pairs the same device in the same second from two source IPs 2 findings

pingid.yml lists both files. The companion security_content PR adds a second unit test
that uses them; the current detection returns 0 on this fixture, the fixed one returns 4.

🤖 Generated with Claude Code

Add five synthetic PingID device-pairing events and six Windows 4723/4724
password events for PingID New MFA Method After Credential Reset.
Cover UPN-to-bare username matching, multiple resets and nearest-reset
selection, exclusion outside the one-hour window, and simultaneous
pairings from distinct source IPs. Register both files in the manifest.

Use lab identities and reserved documentation IPs. Companion to
splunk/security_content#4298.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sbaker-gre
sbaker-gre force-pushed the pingid-credential-reset-upn-fixture branch from 1b08d87 to 65f19f0 Compare September 29, 2026 19:09
sbaker-gre added a commit to sbaker-gre/security_content that referenced this pull request Sep 29, 2026
Normalize UPN and domain-prefixed usernames on both sides of the Windows
password-event join while preserving the original PingID user in findings.
Consider all matching password events and retain the nearest qualifying
reset per complete stats group, preserving source-distinct pairings.

Add the synthetic regression fixture from splunk/attack_data#1230 and
increment the detection version. Local unit tests return two findings for
the original fixture and four for the new fixture. Separate local
assertions verify the exact results and nearest qualifying reset; the
current CI unit runner only requires nonzero results.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant