Browse Rules

Search and filter across all detection sources

258 rules

wazuh low xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

wazuh low xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

wazuh informational xml

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)

sagan low other

AWS STS detected

AWS STS detected

sagan informational other

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartLogging)

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartLogging)

sagan unknown other

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartQuery)

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartQuery)

sagan informational other

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StopLogging)

[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StopLogging)

sagan informational other

[AWS-COGNITO] AWS Cognito event detected (StartUserImportJob)

[AWS-COGNITO] AWS Cognito event detected (StartUserImportJob)

sagan informational other

[AWS-COGNITO] AWS Cognito event detected (StopUserImportJob)

[AWS-COGNITO] AWS Cognito event detected (StopUserImportJob)

sagan critical other

[CISCO-SCA] Stale AWS Access Key

[CISCO-SCA] Stale AWS Access Key

sagan critical other

[CISCO-SCA] AWS EC2 Startup Script Modified

[CISCO-SCA] AWS EC2 Startup Script Modified

sagan medium other

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigRulesEvaluation)

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigRulesEvaluation)

sagan medium other

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigurationRecorder)

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigurationRecorder)

sagan medium other

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StopConfigurationRecorder)

[CLOUDTRAIL] AWS Config cloudtrail event detected - (StopConfigurationRecorder)

sagan medium other

[DYNAMIC] AWS STS logs detected via program.

[DYNAMIC] AWS STS logs detected via program.

anvilogic low other

AWS Storage Enumeration [snowflake-awscloudtrail]

Identify commands associated with enumerating storage services like S3 in AWS -- Threat Actor Association: GUI-vil

anvilogic low spl

AWS Storage Enumeration [splunk-awscloudtrail]

Identify commands associated with enumerating storage services like S3 in AWS -- Threat Actor Association: GUI-vil

panther low python

AWS CloudFormation Stack Drift

A stack has drifted from its defined configuration.

sagan critical other

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/CloudTrailLoggingDisabled)

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/CloudTrailLoggingDisabled)

sagan critical other

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/PasswordPolicyChange)

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/PasswordPolicyChange)

sagan critical other

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:S3/ServerAccessLoggingDisabled)

[AWS-GUARDDUTY] GuardDuty event detected (Stealth:S3/ServerAccessLoggingDisabled)

sagan informational other

[AWS-STS] Security Token Service event detected (AssumeRoleWithSAML)

[AWS-STS] Security Token Service event detected (AssumeRoleWithSAML)

sagan informational other

[AWS-STS] Security Token Service event detected (AssumeRoleWithWebIdentity)

[AWS-STS] Security Token Service event detected (AssumeRoleWithWebIdentity)

sagan informational other

[AWS-STS] Security Token Service event detected (DecodeAuthorizationMessage)

[AWS-STS] Security Token Service event detected (DecodeAuthorizationMessage)

sagan informational other

[AWS-STS] Security Token Service event detected (GetAccessKeyInfo)

[AWS-STS] Security Token Service event detected (GetAccessKeyInfo)