Browse Rules

Search and filter across all detection sources

250 rules

sagan medium other

[DYNAMIC] aws-cloudtrail logs detected via program.

[DYNAMIC] aws-cloudtrail logs detected via program.

chronicle high yara-l

AWS CloudTrail Logging Tampered

Detects when CloudTrail logging is updated, stopped or deleted.

anvilogic low other

AWS Logging Enumeration [snowflake-awscloudtrail]

Threat identifier for AWS API calls associated with logging enumeration.

anvilogic low spl

AWS Logging Enumeration [splunk-awscloudtrail]

Threat identifier for AWS API calls associated with logging enumeration.

panther medium python

AWS CloudTrail Log Validation

This policy ensures that CloudTrail logs have file integrity validation enabled.

panther medium python

AWS CloudTrail Log Encryption

This policy validates that CloudTrail Logs are encrypted at rest with customer managed KMS key.

wazuh informational xml

AWS Cloudtrail: $(aws.eventSource) - $(aws.eventName) - User Login Success.

AWS Cloudtrail: $(aws.eventSource) - $(aws.eventName) - User Login Success.

panther medium python

AWS CloudTrail S3 Bucket Access Logging

This policy validates that the bucket receiving CloudTrail Logs is configured with S3 Access Logging. This audits all creation, modification, or deletion to CloudTrail audit logs.

panther low python

AWS CloudTrail CloudWatch Logs

CloudTrail supports sending data and management events to CloudWatch Logs. This setup can be used for real-time processing of all CloudTrail data events.

splunk unknown spl

AWS Defense Evasion Update Cloudtrail

The following analytic detects `UpdateTrail` events in AWS CloudTrail logs. It identifies attempts to modify CloudTrail settings, potentially to evade logging. The detection leverages CloudTrail logs, focusing on `UpdateTrail` events where the user agent is not the AWS console and the operation is successful. This activity is significant because altering CloudTrail settings can disable or limit logging, hindering visibility into AWS account activities. If confirmed malicious, this could allow at

anvilogic critical other

AWS User Deletion [snowflake-awscloudtrail]

This use case looks for activity of User Deletion for AWS

elastic high kql

AWS CloudTrail Log Suspended

Detects Cloudtrail logging suspension via StopLogging API. Stopping CloudTrail eliminates forward audit visibility and is a classic defense evasion step before sensitive changes or data theft. Investigate immediately and determine what occurred during the logging gap.

panther high python

AWS CloudTrail Management Events Enabled

This policy ensures that at least one CloudTrail has management (control plane) operations logged.

sentinel low kql

AWSCloudTrail - Failed Attempts to Change AWS CloudTrail Logs

Identifies FAILED or denied attempts to manipulate AWS CloudTrail, CloudWatch/EventBridge, or VPC Flow Logs. Successful manipulation is covered by the higher-severity 'AWSCloudTrail - Successful Tampering with AWS CloudTrail Logs' rule. These failed attempts can indicate reconnaissance or an actor probing for insufficient permissions as part of defense evasion. For more information, visit: AWS CloudTrail API: https://docs.aws.amazon.com/awscloudtrail/latest/APIReference/API_Operations.html A

anvilogic high other

CloudTrail Logs Deleted [snowflake-awscloudtrail]

An adversary may delete trails in an attempt to evade defenses. -- Threat Actor Association: LUCR-3

wazuh low xml

AWS Cloudtrail: $(aws.eventSource) - $(aws.eventName) - User Login failed.

AWS Cloudtrail: $(aws.eventSource) - $(aws.eventName) - User Login failed.

anvilogic high other

AWS Failed Console Login [snowflake-awscloudtrail]

Adversaries may attempt to gain access to the AWS console by logging in with guessed or recovered credentials. -- Threat Actor Association: LUCR-3

anvilogic high spl

AWS Failed Console Login [splunk-awscloudtrail]

Adversaries may attempt to gain access to the AWS console by logging in with guessed or recovered credentials. -- Threat Actor Association: LUCR-3

anvilogic high other

AWS EnableAddressTransfer [snowflake-awscloudtrail]

Threat identifier for AWS API call EnableAddressTransfer can be used in Elastic IP Hijacking attack

anvilogic high spl

AWS EnableAddressTransfer [splunk-awscloudtrail]

Threat identifier for AWS API call EnableAddressTransfer can be used in Elastic IP Hijacking attack

anvilogic low other

AWS SES Enumeration [snowflake-awscloudtrail]

Threat identifier for AWS API calls, ListAttachedRolePolicies and ListRolePolicies to identify potential IAM enumeration.

anvilogic low spl

AWS SES Enumeration [splunk-awscloudtrail]

Threat identifier for AWS API calls, ListAttachedRolePolicies and ListRolePolicies to identify potential IAM enumeration.

anvilogic low other

AWS SES Modification [snowflake-awscloudtrail]

Threat identifier for AWS API calls, GetAccount and ListIdentities to identify potential SES enumeration.

anvilogic low spl

AWS SES Modification [splunk-awscloudtrail]

Threat identifier for AWS API calls, GetAccount and ListIdentities to identify potential SES enumeration.

panther high python

Unused AWS Region

CloudTrail logged non-read activity from a verboten AWS region.