PingID credential-reset correlation: normalize usernames and handle multiple resets - #4298
Open
sbaker-gre wants to merge 1 commit into
Open
sbaker-gre wants to merge 1 commit into
sbaker-gre wants to merge 1 commit into
Conversation
sbaker-gre
requested review from
P4T12ICK,
RavenTait,
ljstella,
nasbench,
onurmerdogan,
patel-bhavin,
pyth0n1c,
rosplk and
tccontre
as code owners
September 29, 2026 19:05
Normalize UPN and domain-prefixed usernames on both sides of the Windows password-event join while preserving the original PingID user in findings. Consider all matching password events and retain the nearest qualifying reset per complete stats group, preserving source-distinct pairings. Add the synthetic regression fixture from splunk/attack_data#1230 and increment the detection version. Local unit tests return two findings for the original fixture and four for the new fixture. Separate local assertions verify the exact results and nearest qualifying reset; the current CI unit runner only requires nonzero results. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbaker-gre
added a commit
to sbaker-gre/attack_data
that referenced
this pull request
Sep 29, 2026
Add five synthetic PingID device-pairing events and six Windows 4723/4724 password events for PingID New MFA Method After Credential Reset. Cover UPN-to-bare username matching, multiple resets and nearest-reset selection, exclusion outside the one-hour window, and simultaneous pairings from distinct source IPs. Register both files in the manifest. Use lab identities and reserved documentation IPs. Companion to splunk/security_content#4298. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbaker-gre
force-pushed
the
fix/pingid-credential-reset-user-join
branch
from
September 29, 2026 19:09
f517cc5 to
3dfc0a2
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PingID New MFA Method After Credential Reset can't fire in environments where PingID
usernames are UPNs or email addresses.
The search joins PingID device-pairing events to Windows 4723/4724 on
user. PingIDreports the IdP username (for example
victim_user@example.com), while the Windowspassword events carry the bare account name (
victim_user).upper()alone never makes those match.The shipped fixture uses
victim_useron both sides, so the unit test passes anyway.Changes
join_user, with anyDOMAIN\prefix and@domainsuffix strippedon both sides. The finding keeps the original PingID
user.join max=0, so every password event is considered, not only the first one the subsearchreturns. Previously, a reset logged after the pairing could hide an earlier one that
qualifies.
dedup src, user, action, object, lastTime sortby +timeDiffRaw: one finding perstatsgroup, using the nearest qualifying reset. Pairings from different source IPsstay separate.
user, so it can't overwrite the PingID value.reset after the pairing ahead of one that qualifies, a reset outside the window, and
simultaneous pairings from two IPs.
Verification
current search returns 0. Both pass the original fixture (2 results). Run with
contentctl-ng 1.1.1, Splunk 10.4.3, Splunk_TA_windows 11.0.2 and Splunk_TA_fix_windows.
reset. The current CI unit runner checks for nonzero results; it does not enforce the
exact count or selected reset.
🤖 Generated with Claude Code