Skip to content

PingID credential-reset correlation: normalize usernames and handle multiple resets - #4298

Open
sbaker-gre wants to merge 1 commit into
splunk:developfrom
sbaker-gre:fix/pingid-credential-reset-user-join
Open

sbaker-gre wants to merge 1 commit into
splunk:developfrom
sbaker-gre:fix/pingid-credential-reset-user-join

Conversation

@sbaker-gre

Copy link
Copy Markdown
Contributor

PingID New MFA Method After Credential Reset can't fire in environments where PingID
usernames are UPNs or email addresses.

The search joins PingID device-pairing events to Windows 4723/4724 on user. PingID
reports the IdP username (for example victim_user@example.com), while the Windows
password events carry the bare account name (victim_user). upper() alone never makes those match.
The shipped fixture uses victim_user on both sides, so the unit test passes anyway.

Changes

  • Join on a normalized join_user, with any DOMAIN\ prefix and @domain suffix stripped
    on both sides. The finding keeps the original PingID user.
  • join max=0, so every password event is considered, not only the first one the subsearch
    returns. Previously, a reset logged after the pairing could hide an earlier one that
    qualifies.
  • dedup src, user, action, object, lastTime sortby +timeDiffRaw: one finding per
    stats group, using the nearest qualifying reset. Pairings from different source IPs
    stay separate.
  • The subsearch no longer returns user, so it can't overwrite the PingID value.
  • A second unit test uses the new fixture from T1621 PingID: add UPN and multiple-reset regression fixture attack_data#1230: UPN users, a
    reset after the pairing ahead of one that qualifies, a reset outside the window, and
    simultaneous pairings from two IPs.
  • Version 9 → 10.

Verification

  • Unit tests with the new fixture: fixed search 4 results (expected 1 + 1 + 0 + 2); the
    current search returns 0. Both pass the original fixture (2 results). Run with
    contentctl-ng 1.1.1, Splunk 10.4.3, Splunk_TA_windows 11.0.2 and Splunk_TA_fix_windows.
  • Separate local assertions verified the exact user/source results and nearest qualifying
    reset. The current CI unit runner checks for nonzero results; it does not enforce the
    exact count or selected reset.
  • The new unit test depends on the attack_data PR merging first.

🤖 Generated with Claude Code

Normalize UPN and domain-prefixed usernames on both sides of the Windows
password-event join while preserving the original PingID user in findings.
Consider all matching password events and retain the nearest qualifying
reset per complete stats group, preserving source-distinct pairings.

Add the synthetic regression fixture from splunk/attack_data#1230 and
increment the detection version. Local unit tests return two findings for
the original fixture and four for the new fixture. Separate local
assertions verify the exact results and nearest qualifying reset; the
current CI unit runner only requires nonzero results.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbaker-gre added a commit to sbaker-gre/attack_data that referenced this pull request Sep 29, 2026
Add five synthetic PingID device-pairing events and six Windows 4723/4724
password events for PingID New MFA Method After Credential Reset.
Cover UPN-to-bare username matching, multiple resets and nearest-reset
selection, exclusion outside the one-hour window, and simultaneous
pairings from distinct source IPs. Register both files in the manifest.

Use lab identities and reserved documentation IPs. Companion to
splunk/security_content#4298.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sbaker-gre
sbaker-gre force-pushed the fix/pingid-credential-reset-user-join branch from f517cc5 to 3dfc0a2 Compare September 29, 2026 19:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant