Panther medium experimental python
Amazon Machine Image (AMI) Modified to Allow Public Access
An Amazon Machine Image (AMI) was modified to allow it to be launched by anyone. Any sensitive configuration or application data stored in the AMI's block devices is at risk.
Detection Logic
from panther_aws_helpers import aws_cloudtrail_success, aws_rule_context
from panther_detection_helpers.caching import check_account_age
def rule(event):
# Only check successful ModiyImageAttribute events
if not aws_cloudtrail_success(event) or event.get("eventName") != "ModifyImageAttribute":
return False
added_perms = event.deep_get(
"requestParameters", "launchPermission", "add", "items", default=[{}]
)
for item in added_perms:
if item.get("group") == "all":
return True
if check_account_age(
item.get("userId", "") + "-" + event.udm("user_account_id", default="")
): # checking if the account is new
return True
return False
def alert_context(event):
return aws_rule_context(event) Field Validations
Loading…
Comments (0)
Loading comments...