Browse Rules

Search and filter across all detection sources

1,654 rules

wazuh informational xml

AWS Config - History [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

AWS Config - History [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

wazuh informational xml

AWS Config - Snapshot [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

AWS Config - Snapshot [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

wazuh low xml

AWS Config - Snapshot Compliance [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)] [$(aws.configuration.configRuleList.configRuleName)]: $(aws.resourceId) ($(aws.configurationItemStatus)) $(aws.configuration.complianceType)

AWS Config - Snapshot Compliance [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)] [$(aws.configuration.configRuleList.configRuleName)]: $(aws.resourceId) ($(aws.configurationItemStatus)) $(aws.configuration.complianceType)

wazuh informational xml

The resource was deleted. AWS Config - History: [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

The resource was deleted. AWS Config - History: [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

wazuh informational xml

The resource was newly discovered. AWS Config - History: [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

The resource was newly discovered. AWS Config - History: [$(aws.awsAccountId) $(aws.awsRegion)] [$(aws.resourceType)]: $(aws.resourceId) ($(aws.configurationItemStatus))

wazuh informational xml

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type) - $(aws.userIdentity.userName) - $(aws.sourceIPAddress)

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type) - $(aws.userIdentity.userName) - $(aws.sourceIPAddress)

wazuh informational xml

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type) - $(aws.userIdentity.userName) - $(aws.sourceIPAddress)

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type) - $(aws.userIdentity.userName) - $(aws.sourceIPAddress)

wazuh informational xml

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

wazuh low xml

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

wazuh low xml

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

wazuh medium xml

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

wazuh high xml

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

AWS Macie $(aws.severity): $(aws.name) - $(aws.summary.description)

wazuh informational xml

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

wazuh medium xml

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

wazuh low xml

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

wazuh low xml

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

wazuh informational xml

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

AWS Inspector - Network assessment [$(aws.createdAt)]: $(aws.title) [$(aws.severity)]

wazuh low xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

wazuh low xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

wazuh informational xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

wazuh informational xml

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type)

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type)

wazuh informational xml

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type)

AWS KMS: [$(aws.eventName)] $(aws.userIdentity.type)

wazuh informational xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

wazuh low xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

wazuh medium xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)