Skip to content
This repository was archived by the owner on Dec 27, 2022. It is now read-only.

Commit c8d3e11

Browse files
Add files via upload
0 parents  commit c8d3e11

File tree

4 files changed

+610
-0
lines changed

4 files changed

+610
-0
lines changed

CONTRIBUTING.md

+50
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# Welcome #
2+
3+
We're so glad you're thinking about contributing to this open source
4+
project! If you're unsure or afraid of anything, just ask or submit
5+
the issue or pull request anyway. The worst that can happen is that
6+
you'll be politely asked to change something. We appreciate any sort
7+
of contribution, and don't want a wall of rules to get in the way of
8+
that.
9+
10+
Before contributing, we encourage you to read our CONTRIBUTING policy
11+
(you are here), our [LICENSE](LICENSE), and our [README](README.md),
12+
all of which should be in this repository.
13+
14+
## Issues ##
15+
16+
If you want to report a bug or request a new feature, the most direct
17+
method is to [create an
18+
issue](https://github.com/cisagov/hawk/issues) in this
19+
repository. We recommend that you first search through existing
20+
issues (both open and closed) to check if your particular issue has
21+
already been reported. If it has then you might want to add a comment
22+
to the existing issue. If it hasn't then feel free to create a new
23+
one.
24+
25+
## Pull requests ##
26+
27+
If you choose to [submit a pull
28+
request](https://github.com/cisagov/hawk/pulls), you will
29+
notice that our continuous integration (CI) system runs a fairly
30+
extensive set of linters and syntax checkers. Your pull request may
31+
fail these checks, and that's OK. If you want you can stop there and
32+
wait for us to make the necessary corrections to ensure your code
33+
passes the CI checks.
34+
35+
If you want to make the changes yourself, or if you want to become a
36+
regular contributor, then you will want to set up
37+
[pre-commit](https://pre-commit.com/) on your local machine. Once you
38+
do that, the CI checks will run locally before you even write your
39+
commit message. This speeds up your development cycle considerably.
40+
41+
## Public domain ##
42+
43+
This project is in the public domain within the United States, and
44+
copyright and related rights in the work worldwide are waived through
45+
the [CC0 1.0 Universal public domain
46+
dedication](https://creativecommons.org/publicdomain/zero/1.0/).
47+
48+
All contributions to this project will be released under the CC0
49+
dedication. By submitting a pull request, you are agreeing to comply
50+
with this waiver of copyright interest.

LICENSE

+116
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,116 @@
1+
CC0 1.0 Universal
2+
3+
Statement of Purpose
4+
5+
The laws of most jurisdictions throughout the world automatically confer
6+
exclusive Copyright and Related Rights (defined below) upon the creator and
7+
subsequent owner(s) (each and all, an "owner") of an original work of
8+
authorship and/or a database (each, a "Work").
9+
10+
Certain owners wish to permanently relinquish those rights to a Work for the
11+
purpose of contributing to a commons of creative, cultural and scientific
12+
works ("Commons") that the public can reliably and without fear of later
13+
claims of infringement build upon, modify, incorporate in other works, reuse
14+
and redistribute as freely as possible in any form whatsoever and for any
15+
purposes, including without limitation commercial purposes. These owners may
16+
contribute to the Commons to promote the ideal of a free culture and the
17+
further production of creative, cultural and scientific works, or to gain
18+
reputation or greater distribution for their Work in part through the use and
19+
efforts of others.
20+
21+
For these and/or other purposes and motivations, and without any expectation
22+
of additional consideration or compensation, the person associating CC0 with a
23+
Work (the "Affirmer"), to the extent that he or she is an owner of Copyright
24+
and Related Rights in the Work, voluntarily elects to apply CC0 to the Work
25+
and publicly distribute the Work under its terms, with knowledge of his or her
26+
Copyright and Related Rights in the Work and the meaning and intended legal
27+
effect of CC0 on those rights.
28+
29+
1. Copyright and Related Rights. A Work made available under CC0 may be
30+
protected by copyright and related or neighboring rights ("Copyright and
31+
Related Rights"). Copyright and Related Rights include, but are not limited
32+
to, the following:
33+
34+
i. the right to reproduce, adapt, distribute, perform, display, communicate,
35+
and translate a Work;
36+
37+
ii. moral rights retained by the original author(s) and/or performer(s);
38+
39+
iii. publicity and privacy rights pertaining to a person's image or likeness
40+
depicted in a Work;
41+
42+
iv. rights protecting against unfair competition in regards to a Work,
43+
subject to the limitations in paragraph 4(a), below;
44+
45+
v. rights protecting the extraction, dissemination, use and reuse of data in
46+
a Work;
47+
48+
vi. database rights (such as those arising under Directive 96/9/EC of the
49+
European Parliament and of the Council of 11 March 1996 on the legal
50+
protection of databases, and under any national implementation thereof,
51+
including any amended or successor version of such directive); and
52+
53+
vii. other similar, equivalent or corresponding rights throughout the world
54+
based on applicable law or treaty, and any national implementations thereof.
55+
56+
2. Waiver. To the greatest extent permitted by, but not in contravention of,
57+
applicable law, Affirmer hereby overtly, fully, permanently, irrevocably and
58+
unconditionally waives, abandons, and surrenders all of Affirmer's Copyright
59+
and Related Rights and associated claims and causes of action, whether now
60+
known or unknown (including existing as well as future claims and causes of
61+
action), in the Work (i) in all territories worldwide, (ii) for the maximum
62+
duration provided by applicable law or treaty (including future time
63+
extensions), (iii) in any current or future medium and for any number of
64+
copies, and (iv) for any purpose whatsoever, including without limitation
65+
commercial, advertising or promotional purposes (the "Waiver"). Affirmer makes
66+
the Waiver for the benefit of each member of the public at large and to the
67+
detriment of Affirmer's heirs and successors, fully intending that such Waiver
68+
shall not be subject to revocation, rescission, cancellation, termination, or
69+
any other legal or equitable action to disrupt the quiet enjoyment of the Work
70+
by the public as contemplated by Affirmer's express Statement of Purpose.
71+
72+
3. Public License Fallback. Should any part of the Waiver for any reason be
73+
judged legally invalid or ineffective under applicable law, then the Waiver
74+
shall be preserved to the maximum extent permitted taking into account
75+
Affirmer's express Statement of Purpose. In addition, to the extent the Waiver
76+
is so judged Affirmer hereby grants to each affected person a royalty-free,
77+
non transferable, non sublicensable, non exclusive, irrevocable and
78+
unconditional license to exercise Affirmer's Copyright and Related Rights in
79+
the Work (i) in all territories worldwide, (ii) for the maximum duration
80+
provided by applicable law or treaty (including future time extensions), (iii)
81+
in any current or future medium and for any number of copies, and (iv) for any
82+
purpose whatsoever, including without limitation commercial, advertising or
83+
promotional purposes (the "License"). The License shall be deemed effective as
84+
of the date CC0 was applied by Affirmer to the Work. Should any part of the
85+
License for any reason be judged legally invalid or ineffective under
86+
applicable law, such partial invalidity or ineffectiveness shall not
87+
invalidate the remainder of the License, and in such case Affirmer hereby
88+
affirms that he or she will not (i) exercise any of his or her remaining
89+
Copyright and Related Rights in the Work or (ii) assert any associated claims
90+
and causes of action with respect to the Work, in either case contrary to
91+
Affirmer's express Statement of Purpose.
92+
93+
4. Limitations and Disclaimers.
94+
95+
a. No trademark or patent rights held by Affirmer are waived, abandoned,
96+
surrendered, licensed or otherwise affected by this document.
97+
98+
b. Affirmer offers the Work as-is and makes no representations or warranties
99+
of any kind concerning the Work, express, implied, statutory or otherwise,
100+
including without limitation warranties of title, merchantability, fitness
101+
for a particular purpose, non infringement, or the absence of latent or
102+
other defects, accuracy, or the present or absence of errors, whether or not
103+
discoverable, all to the greatest extent permissible under applicable law.
104+
105+
c. Affirmer disclaims responsibility for clearing rights of other persons
106+
that may apply to the Work or any use thereof, including without limitation
107+
any person's Copyright and Related Rights in the Work. Further, Affirmer
108+
disclaims responsibility for obtaining any necessary consents, permissions
109+
or other rights required for any use of the Work.
110+
111+
d. Affirmer understands and acknowledges that Creative Commons is not a
112+
party to this document and has no duty or obligation with respect to this
113+
CC0 or use of the Work.
114+
115+
For more information, please see
116+
<http://creativecommons.org/publicdomain/zero/1.0/>

README.md

+69
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
# Sparrow.ps1 #
2+
3+
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment. The tool is intended for use by incident responders, and focuses on the narrow scope of user and application activity endemic to identity and authentication based attacks seen recently in multiple sectors. It is neither comprehensive nor exhaustive of available data, and is intended to narrow a larger set of available investigation modules and telemetry to those specific to recent attacks on federated identity sources and applications.
4+
5+
Sparrow.ps1 will check and install the required PowerShell modules on the analysis machine, check the unified audit log in Azure/M365 for certain indicators of compromise (IoC's), list Azure AD domains, and check Azure service principals and their Microsoft Graph API permissions to identify potential malicious activity. The tool then outputs the data into multiple CSV files in a default directory.
6+
7+
## Requirements ##
8+
9+
The following AzureAD/m365 permissions are required to run Sparrow.ps1, and provide it read-only access to the Tenant.
10+
11+
- Azure Active Directory:
12+
- Security Reader
13+
- Security and Compliance Center:
14+
- Compliance Adminstrator
15+
- Exchange Online Admin Center: Utilize a custom group for these specific permissions:
16+
- Mail Recipients
17+
- Security Group Creation and Membership
18+
- User options
19+
- View-Only Audit log
20+
- View-Only Configuration
21+
- View-Only Recipients
22+
23+
To check for the MailItemsAccessed Operation, your tenant organization requires an Office 365 or Microsoft 365 E5/G5 license.
24+
25+
## Installation ##
26+
27+
Sparrow.ps1 does not require any extra steps for installation once the permissions detailed in Requirements are satisfied.
28+
29+
The function, Check-PSModules, will check to see if the three required PowerShell modules are installed on the system and if not, it will use the default PowerShell repository on the system to reach out and install. If the modules are present but not imported, the script will also import the missing modules so that they are ready for use.
30+
31+
The required PowerShell modules:
32+
33+
- CloudConnect (https://www.powershellgallery.com/packages/CloudConnect/1.1.2)
34+
- AzureAD (https://www.powershellgallery.com/packages/AzureAD/2.0.2.128)
35+
- MSOnline (https://www.powershellgallery.com/packages/MSOnline/1.1.183.57)
36+
37+
## Usage ##
38+
39+
To use Sparrow.ps1, type the following command into a PowerShell window (assuming file is in your working directory):
40+
41+
`.\Sparrow.ps1`
42+
43+
## Issues ##
44+
45+
If you have issues using the code, open an issue on the repository!
46+
47+
You can do this by clicking "Issues" at the top and clicking "New Issue" on the following page.
48+
49+
## Contributing ##
50+
51+
We welcome contributions! Please see [here](CONTRIBUTING.md) for details.
52+
53+
## License ##
54+
55+
This project is in the worldwide [public domain](LICENSE).
56+
57+
This project is in the public domain within the United States, and copyright and related rights in the work worldwide are waived through the [CC0 1.0 Universal public domain dedication](https://creativecommons.org/publicdomain/zero/1.0/).
58+
59+
All contributions to this project will be released under the CC0 dedication. By submitting a pull request, you are agreeing to comply with this waiver of copyright interest.
60+
61+
## Legal Disclaimer ##
62+
63+
NOTICE
64+
65+
This software package (“software” or “code”) was created by the United States Government and is not subject to copyright. You may use, modify, or redistribute the code in any manner. However, you may not subsequently copyright the code as it is distributed. The United States Government makes no claim of copyright on the changes you effect, nor will it will it restrict your distribution of bona fide changes to the software. If you decide to update or redistribute the code, please include this notice with the code. Where relevant, we ask that you credit the Cybersecurity and Infrastructure Security Agency with the following statement: “Original code developed by the Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security.”
66+
67+
USE THIS SOFTWARE AT YOUR OWN RISK. THIS SOFTWARE COMES WITH NO WARRANTY, EITHER EXPRESS OR IMPLIED. THE UNITED STATES GOVERNMENT ASSUMES NO LIABILITY FOR THE USE OR MISUSE OF THIS SOFTWARE OR ITS DERIVATIVES.
68+
69+
THIS SOFTWARE IS OFFERED “AS-IS.” THE UNITED STATES GOVERNMENT WILL NOT INSTALL, REMOVE, OPERATE OR SUPPORT THIS SOFTWARE AT YOUR REQUEST. IF YOU ARE UNSURE OF HOW THIS SOFTWARE WILL INTERACT WITH YOUR SYSTEM, DO NOT USE IT.

0 commit comments

Comments
 (0)