Panther informational experimental python
EC2 Security Group Modified
An EC2 Security Group was modified.
Detection Logic
from panther_aws_helpers import aws_cloudtrail_success, aws_rule_context
# API calls that are indicative of an EC2 SecurityGroup modification
EC2_SG_MODIFIED_EVENTS = {
"AuthorizeSecurityGroupIngress",
"AuthorizeSecurityGroupEgress",
"RevokeSecurityGroupIngress",
"RevokeSecurityGroupEgress",
"CreateSecurityGroup",
"DeleteSecurityGroup",
}
def rule(event):
return aws_cloudtrail_success(event) and event.get("eventName") in EC2_SG_MODIFIED_EVENTS
def dedup(event):
return event.get("recipientAccountId")
def alert_context(event):
return aws_rule_context(event) Field Validations
Loading…
Comments (0)
Loading comments...