Browse Rules

Search and filter across all detection sources

372 rules

wazuh informational xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

wazuh low xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

wazuh medium xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title) [IP: $(aws.service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4)] [Port: $(aws.service.action.portProbeAction.portProbeDetails.localPortDetails.port)]

wazuh informational xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

wazuh low xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

wazuh medium xml

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

AWS GuardDuty: $(aws.service.action.actionType) - $(aws.title)

sagan medium other

[EXTRAHOP] AWS Cloud Service Enumeration

[EXTRAHOP] AWS Cloud Service Enumeration

panther informational python

AWS Config Service Created

An AWS Config Recorder or Delivery Channel was created

chronicle high yara-l

AWS Config Service Modified

Detects when AWS Config Service is updated, stopped or deleted.

panther medium python

AWS CloudTrail SES Enumeration

sagan informational other

[AWS-STS] Security Token Service event detected (AssumeRoleWithSAML)

[AWS-STS] Security Token Service event detected (AssumeRoleWithSAML)

sagan informational other

[AWS-STS] Security Token Service event detected (AssumeRoleWithWebIdentity)

[AWS-STS] Security Token Service event detected (AssumeRoleWithWebIdentity)

sagan informational other

[AWS-STS] Security Token Service event detected (DecodeAuthorizationMessage)

[AWS-STS] Security Token Service event detected (DecodeAuthorizationMessage)

sagan informational other

[AWS-STS] Security Token Service event detected (GetAccessKeyInfo)

[AWS-STS] Security Token Service event detected (GetAccessKeyInfo)

sagan informational other

[AWS-STS] Security Token Service event detected (GetFederationToken)

[AWS-STS] Security Token Service event detected (GetFederationToken)

sagan informational other

[AWS-STS] Security Token Service event detected (GetSessionToken)

[AWS-STS] Security Token Service event detected (GetSessionToken)

panther high python

AWS Potentially Stolen Service Role

A role was assumed by an AWS service, followed by a user within 24 hours. This could indicate a stolen or compromised AWS service role.

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccount)

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccount)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccountSendingEnabled)

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccountSendingEnabled)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (ListIdentities)

[AWS-SES] Simple Email Service Discovery Event Detected (ListIdentities)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (ListVerifiedEmailAddresses)

[AWS-SES] Simple Email Service Discovery Event Detected (ListVerifiedEmailAddresses)

sagan medium other

[EXTRAHOP] AWS Instance Metadata Service (IMDS) Proxy

[EXTRAHOP] AWS Instance Metadata Service (IMDS) Proxy

sagan unknown other

[AWS-SES] Simple Email Service Discovery Command Event Detected (GetSendQuota)

[AWS-SES] Simple Email Service Discovery Command Event Detected (GetSendQuota)

sagan informational other

[AWS-STS] Security Token Service Discovery Command Event Detected (GetCallerIdentity)

[AWS-STS] Security Token Service Discovery Command Event Detected (GetCallerIdentity)

anvilogic high spl

AWS DisableAWSServiceAccess [splunk-awscloudtrail]

The DisableAWSServiceAccess API call in AWS CloudTrail indicates when a service-linked role is being disabled for an AWS service. Service-linked roles are used by AWS services to perform actions on your behalf, and disabling them can prevent those services from operating properly. This use case detects attempts to disable service-linked roles via the DisableAWSServiceAccess API call in AWS CloudTrail. Such activity may indicate efforts to disrupt or evade monitoring services, particularly if per