Report Templates
The following modular objective templates can be used as a basis for your own objectives.
The objective types may be altered via configuring your objective, and selecting 'Change Type' in the top right corner. This will display a list of Objective Types to select from.
Win Security
Oracle Server
Oracle Start Stop Log
Display Oracle startup and shutdown events.
Windows File Objectives
Windows Object Permission Changes
Monitor permission changes to a file or directory that is considered sensitive. Note that to use this objective, the Snare agents must be configured to report on event 4670.
Windows File Access
Monitor access to file and directories that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to report on file accesses.
User Login
Type 3 and Type 10 Network logins
This objective displays Windows Type 3 host to host network logins and Type 10 RDP network logins.
User Interactive Logins and Logoffs
This objective is used to monitor interactive account login and logoff events. This includes workstation locked/unlocked events and screen saver invoked/dismissed events.
Failed User Logins
This objective is used to monitor failed user login actions on Windows servers.
User Login
This objective is used to monitor user login actions on Windows servers.
Administrative Actions
Service was installed
This objective displays when a service is installed on the system.
Audit Log Cleared
This objective checks to see if the Windows event logs were cleared. Note that the Snare Agent must be configured to collect these events. The clearing of an event log may indicate that a user is attempting to cover their tracks.
Local Account added to Administrators
This objective displays Windows local accounts that have been added to the Local Administrators Group.
Startup Run Tasks Alert
This objective displays when the Run and RunOnce registry keys have been modified.
Changes to the Audit Policy
Although the Snare for Windows agent is able to configure the hosts audit sub-system, this objective keeps an eye on events which indicate an attempt to change the underlying audit configuration. Changes to the underlying audit subsystem may indicate a user that is attempting to hide their "tracks", or attempting to obscure their (potentially) unauthorized activity.
Account Creation and Deletion on Windows and ACF2
This objective displays any differences between Windows and ACF2 account creation details. In particular, the objective will display:
1) Account Creation and Removal for ACF2, that does not have a corresponding create/remove for Windows, and
2) Display Account Creation and Removal for Windows, that does not have a corresponding create/remove for ACF2.
Group Member Changes
This objective shows changes to the members of sensitive Windows Groups.
Scheduled task was created
This objective displays when a new scheduled task has been created.
Account Creation and Deletion
This objective displays Windows accounts (in specified domains) that have been recently created or deleted.
User Modifications
This objective shows modifications to specified sensitive Windows users.
Group Creation and Deletion
This objective displays Windows groups that have been recently created or deleted.
Privilege Escalation
This objective displays Windows user rights changes to allow monitoring for escalation of user privileges.
Group Modifications
This objective shows modifications to specified sensitive Windows groups.
Process Objectives
New Process Created
Monitor when new processes are created.
Windows Process Access
Monitor access to applications that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to report on process execution.
Win Application
Administrative Activity
Application Crash
This objective is used to monitor crashed applications.
NetIQ User Administrative Activity
This objective is used to monitor user administrative activity using the NetIQ product.
NetIQ Group Administrative Activity
This objective is used to monitor group administrative activity using the NetIQ product.
EMET Failures
This objective is used to monitor error messages from Microsoft's Enhanced Mitigation Experience Toolkit.
Windows File Protection
The Windows File Protection service monitors critical system files and attempts to prevent unauthorized software from modifying or replacing these files. This objective is used to monitor WFP warning events.
NetIQ Administrative Activity
This objective is used to monitor administrative activity using the NetIQ product.
Win System
Administrative Actions
Windows 2008R2 Non-Security Audit Log Cleared
This objective checks to see if the Windows Application, System or another non-security event log was cleared. Note that the Snare agent must be configured to collect these events.
Audit Log Corrupt
Display Windows machines that have reported a corrupt event log, during the reporting period. Corrupt event log reporting is only available in Snare for Windows version 3.0.0 and above.
Linux Audit
User Login
User Login
This objective is used to monitor user login actions on Linux servers.
Process Objectives
Executing a Process
This objective is used to monitor access to processes or applications that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to collect process events.
File Objectives
Accessing a File
This objective is used to monitor access to files that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to collect file events.
Account Management Objectives
Account Management
This objective is used to monitor account management actions on Linux Servers. Note that the Linux audit subsystem will only generate events when an account or group, is modified using account management binaries. Situations where a root user manually modifies the /etc/passwd or /etc/group files, will not be detected by this objective.
User Account Management
This objective is used to monitor user account management actions on Linux Servers. Note that the Linux audit subsystem will only generate events when an account or group, is modified using account management binaries. Situations where a root user manually modifies the /etc/passwd or /etc/group files will not be detected by this objective.
Group Account Management
This objective is used to monitor group account management actions on Linux Servers. Note that the Linux audit subsystem will only generate events when an account or group, is modified using account management binaries. Situations where a root user manually modifies the /etc/passwd or /etc/group files, will not be detected by this objective.
SOCKS Log
User Authentication
Failed Authentication
This objective looks for failed authentication events from a SOCKS server.
MS DNS Server
MSDNSServer
Microsoft DNS Server Logs. DNS over TCP
This objective is used to monitor DNS over TCP suspicious usage.
Microsoft DNS Server Logs. DNS Server Failure
This objective is used to monitor DNS Server Response Failure.
Microsoft DNS Server Logs. DNS Client IP Find
This objective is used to retrieve DNS traffic from/to IP.
Microsoft DNS Server Logs. NXDOMAIN
This objective is used to monitor Non Existent Domains DNS Queries Only.
Universal Log
Report Access
Reading Reports
This objective allows you to search for reports that have been read.
Search Analysis
Query Term Analysis
This objective allows you to monitor the search terms used in Universal Log data, based on a 'Query' event in the 'Message' field.
User Login
User Login
This objective allows you to monitor user logins reported in the Universal Log data.
Report Prints
Print Reports
This objective allows you to search for reports that have been printed.
Solaris BSM
File Access
Access to Sensitive Files
Monitor access to file and directories that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to report on file accesses.
User Login
User Login
This objective is used to monitor user login actions on Solaris servers.
User Privilege Escalation
Access to a target account
This objective is used to monitor access to a target account through the /bin/su utility.
Failed access to a user account
This objective is used to monitor failed access to a target account through the /bin/su utility.
Process Objectives
Executing a Process
This objective is used to monitor access to processes or applications that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to
collect process events.
RACF Log
User Login
User Logins
This objective displays information relating to RACF user logins.
Object Access
Access to RACF Resources
This objective monitors access to RACF resources that are considered to be sensitive. A ReturnCode of 0 implies a failed attempt to access the resource. Use the RESOURCE field to narrow your search criteria.
Configuration Check
CISCO Configuration Checker
CISCO Pix/Router Configuration Checker
Compare the current CISCO Pix or Router configuration to an authorised version. The objective will attempt to connect to the device using the 'telnet' protocol and display the current configuration. The current configuration will also be compared against an authorized 'Master' and changes will be highlighted. Two passwords in the "Configure" section (connect, and enable) are used to retrieve the configuration.
Network Mapper
Network Mapping and Vulnerability Scan
Network Mapper
This objective allows you to scan your network for open services. New systems, or systems with unauthorized ports, will be highlighted for your attention. In addition, an optional network security scan can be conducted against any hosts that are found. The report may be displayed in tabular format, which is useful for the analysis of many hosts on any given network. In both "iconized" and "tabular" formats, an authorized "port list" can be configured on a host-by-host basis. Future scans against the host in question will highlight any changes in port activation or deactivation. The network scanner can be configured to scan both TCP and/or UDP port ranges.
UDP scanning is very slow and should be used with care. This is because UDP will always have to wait for a timeout to determine if a port is closed. If this timeout is too short, then it will miss valid ports and not correctly report. This objective uses the free Open Source tool, NMAP. NMap is used to determine the open ports on one or more hosts. Further details are available from: http://www.insecure.org/
User/Group Snapshot
Account Flags
Account Flags
This objective displays those users who have settings configured on their account that are considered sensitive or important from a security viewpoint. These attributes are queried on a regular basis by connecting to specified Snare Agents. The updated information will be displayed in these reports, on a scheduled basis, as required by the users of these objectives.
Account Expiry
Account Expiry
This objective displays account expiry settings (in days) by system and/or domain. Please note that this objective requires Snare for Windows version 2.6.2 or later. For accounts retrieved from the Windows Active Directory interface, the objective reports the current maximum time since any non-expired user has changed their password, which should generally provide an approximation of probable server password expiry settings in most circumstances.
Sensitive Groups
Sensitive Groups
This objective takes snapshots of the applicable group memberships and compares them to a specified list to report on authorized and unauthorized group members. The Snare Central will regularly query the specified server(s) to determine the members of all groups. This is then used by these objectives to determine which users have been authorized to be members of this group, and which are not.
Tru64 Audit
User Login
User Login
This objective is used to monitor user login actions on Tru64 servers.
File Access
Access to Sensitive Files
Monitor access to file and directories that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to report on file accesses.
User Privilege Escalation
User access to a target account
This objective is used track access to a target account through the /bin/su utility.
Gauntlet Firewall Log
Electronic Mail
Electronic Mail events
The Gauntlet firewall generates events based on the email addresses that have been sent through the firewall. This objective allows the user to report on email information derived
from the Gauntlet Firewall logs.
ACF2 Log
Account Administration
Changes to Accounts
This objective displays information relating to ACF2 account modifications. ACF2 logs can be collected from an IBM MVS mainframe, and analysed using the Snare Central. The logs from the ACF2 mainframe are collected via FTP or SCP file transfer into the /data/SnareCollect/ACF2Log/ directory on the Snare Central.
Accounts Created or Deleted
This objective displays those ACF2 users on an MVS host which have been created or deleted.
Changes to Flags
For each CHANGE, DELETE or INSERT, this objective displays the details of the ACF2 changes on an MVS host.
Object Access
Access to the ACF2 Resources
This objective monitors access to MVS resources that are considered to be sensitive. Use the RESOURCE field to narrow your search criteria. A ReturnCode of VIOLATION, or *VIO, indicates a failed attempt to access the resource
Access to the INFOSTORE database
The Infostore database (ACF60STO) is a sensitive repository of ACF2 information. This objective displays events relating to user access to the INFOSTORE database.
User Login Failures
User Login Failures
This objective displays information relating to ACF2 user login failures.
Rule Changes
ACF2 Rule Changes
This objective displays events relating to changes to Rules. The ability to change ACF2 rules on MVS systems indicates privileged access. This objective is able to monitor anyone that has been modifying these rules. The changing of ACF2 (on those MVS systems that use ACF2) should be carefully monitored to ensure only authorized users are undertaking authorized activity. This objective is able to maintain a view of actions undertaken in this security management activity.
Object Access
Object Access
Access to Lotus Notes Resources
This objective monitors access to Lotus Notes Database Resources. Use the OBJECT field to narrow your search criteria.
Access to the ACF2 Resources
This objective monitors access to ACF2 Objects that are considered to be sensitive. Use the OBJECT field to narrow your search criteria.
PIX Log
Authentication
User Authentication events
Display user authentication events
SonicWall
Packet Logs
Dropped Packets
Display events that have a category that indicates dropped packets
Apple BSM
Process Objectives
Executing a Process
This objective is used to monitor access to processes or applications that are considered to be sensitive. Note that to use this objective, the Snare agents must be configured to
collect process events.
User Privilege Escalation
Failed access to a user account
This objective is used to monitor failed access to a target account through the /bin/su utility.
Access to a target account
This objective is used to monitor failed access to a target account through the /bin/su utility.
User Login
User Login
This objective is used to monitor user login actions on Apple servers.
File Access
Access to Sensitive Files
Monitor access to file and directories that are considered to be sensitive. Note that to use this objective, the Snare agents must be configured to report on file accesses
AIX Audit
Process Objectives
Executing a Process
This objective is used to monitor access to processes or applications that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to collect process events.
User SU
User access to the root account
This objective is used to monitor access to the root account through the /bin/su utility.
User Login
User Login
This objective is used to monitor user login actions on AIX servers. Note that FTP access is also counted as a 'login', but protocols such as SSH or VNC may not generate a login event. It is important that the 'Configure' section of the objective be used to define from which system(s) the login events are required, so that the user(s) of this objective are not flooded with too many login events. This will especially be the case in agencies that are of a significant size, and are collecting events from numerous AIX hosts.
File Access
Access to Sensitive Files
Monitor access to file and directories that are considered to be sensitive. Note that to use this objective, the Snare Agents must be configured to report on file accesses.
Nortel VPN Router
Configuration Changes
Configuration Changes
This objective will watch for configuration changes to Nortel VPN Routers - such as the creation, destruction, or modification of particular configuration items.
Authentication Events
Failed Logins
This objective will scan for failed attempts to access the VPN device by searching for events that include "Failed Login Attempt" or "failed to log in".
Successful Logins
This objective will scan for successful logins to the VPN device by searching for events that include "logged in from", "logged into group" or "login by using".
IP Tables Firewall
Non-Local Network Connections
Dropped Non-Local Network Connections
Display dropped packets that do not have a source address of a routable IP block
Accepted Non-Local Network Connections
Display non-dropped packets that have a source address of a routable IP block
Local Network Connections
Accepted Local Network Connections
Display non-dropped packets that have a source address of a non-routable IP block
Dropped Local Network Connections
Display dropped packets that have a source address of a non-routable IP block
Browser
Browser Objectives
Access to Social Media and Related Sites
Scan for access to social media and related sites. Please unlock this objective, and modify according to your requirements.
Cookie Modifications
Display cookie related events from Snare Browser agents.
Inappropriate material
Display inappropriate material, accessed through a browser.
INAPPROPRIATE CONTENT MAY BE DISPLAYED WITH THIS RANDOM SAMPLE.
The images are linked directly to the target site. This means that your UserID will download the images through your proxy server (if enabled), which means you may appear in your own logs.
Please also note that:1) The originating user may not have deliberately accessed the content in question - it may have been a popup caused by a rogue web site, and2) The image may no longer exist on the target site, in which case, you will receive a 'no image' placeholder within your web browser.