-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
aws_new_rules #5021
base: master
Are you sure you want to change the base?
aws_new_rules #5021
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please provide log example in order for me to verify the logic of the rules.
rules/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failure.yml
Outdated
Show resolved
Hide resolved
rules/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failure.yml
Outdated
Show resolved
Hide resolved
rules/cloud/aws/cloudtrail/aws_cloudtrail_console_susp_login.yml
Outdated
Show resolved
Hide resolved
In AWS logs, "eventName" and "status" fields are mainly used to detect events. Events can be found here (for example): Some alerts may be developed for preventive detection and it is not always possible to quickly find logs at hand. |
Hi! |
In progress :) |
Summary of the Pull Request
Changelog
Example Log Event
Fixed Issues
SigmaHQ Rule Creation Conventions