Search and filter across all detection sources
258 rules
AWS Trusted Advisor - [$(aws.uuid)] [$(aws.check-name)]: $(aws.status)
AWS STS detected
[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartLogging)
[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StartQuery)
[AWS-CLOUDTRAIL] AWS Cloudtrail event detected (StopLogging)
[AWS-COGNITO] AWS Cognito event detected (StartUserImportJob)
[AWS-COGNITO] AWS Cognito event detected (StopUserImportJob)
[CISCO-SCA] Stale AWS Access Key
[CISCO-SCA] AWS EC2 Startup Script Modified
[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigRulesEvaluation)
[CLOUDTRAIL] AWS Config cloudtrail event detected - (StartConfigurationRecorder)
[CLOUDTRAIL] AWS Config cloudtrail event detected - (StopConfigurationRecorder)
[DYNAMIC] AWS STS logs detected via program.
AWS Storage Enumeration [snowflake-awscloudtrail]
Identify commands associated with enumerating storage services like S3 in AWS -- Threat Actor Association: GUI-vil
AWS Storage Enumeration [splunk-awscloudtrail]
AWS CloudFormation Stack Drift
A stack has drifted from its defined configuration.
[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/CloudTrailLoggingDisabled)
[AWS-GUARDDUTY] GuardDuty event detected (Stealth:IAMUser/PasswordPolicyChange)
[AWS-GUARDDUTY] GuardDuty event detected (Stealth:S3/ServerAccessLoggingDisabled)
[AWS-STS] Security Token Service event detected (AssumeRoleWithSAML)
[AWS-STS] Security Token Service event detected (AssumeRoleWithWebIdentity)
[AWS-STS] Security Token Service event detected (DecodeAuthorizationMessage)
[AWS-STS] Security Token Service event detected (GetAccessKeyInfo)