- AWS ACM Certificate Expiration
- When a certificate is 60 days away from expiration, ACM automatically attempts to renew it every hour.
- AWS ACM Certificate Status
- This policy checks if an ACM certificate renewal is pending or has failed and is in use by any other resources within the account.
- AWS ACM Secure Algorithms
- This policy validates that all ACM certificates are using secure key and signature algorithms.
- AWS CloudFormation Stack Drift
- A stack has drifted from its defined configuration.
- AWS CloudFormation Stack IAM Service Role
- Associating IAM roles with CloudFormation stacks ensures least privilege when making changes to your account.
- AWS CloudFormation Stack Termination Protection
- Protects a CloudFormation stack from accidentally being deleted. If you attempt to delete a stack with termination protection enabled, the deletion fails and the stack, including its status, will remain unchanged.
- A CloudTrail Was Created or Updated
- A CloudTrail Trail was created, updated, or enabled.
- Account Security Configuration Changed
- An account wide security configuration was changed.
- Amazon Machine Image (AMI) Modified to Allow Public Access
- An Amazon Machine Image (AMI) was modified to allow it to be launched by anyone. Any sensitive configuration or application data stored in the AMI's block devices is at risk.
- Anomalous AccessDenied Requests
- ARNs with a high Access Denied error rate could indicate an error or compromised credentials attempting to perform reconnaissance.
- AWS Authentication from CrowdStrike Unmanaged Device
- Detects AWS Authentication events with IP Addresses not found in CrowdStrike's AIP List
- AWS Authentication from CrowdStrike Unmanaged Device (crowdstrike_fdrevent table)
- Detects AWS Authentication events with IP Addresses not found in CrowdStrike's AIP List
- AWS Backdoor Administrative IAM Role Created
- Identifies when CreateRole and AttachAdminRolePolicy CloudTrail events occur in a short period of time. This sequence could indicate a potential security breach.
- AWS Bedrock Guardrail Updated or Deleted
- An Amazon Bedrock Guardrail was updated or deleted. Amazon Bedrock Guardrails are used to implement application-specific safeguards based on your use cases and responsible AI policies. Updating or deleting a guardrail can have security implications to your AI workloads.
- AWS Bedrock Model Invocation Logging Configuration Deleted
- An Amazon Bedrock Model Invocation Logging Configuration was deleted. Use model invocation logging to collect metadata, requests, and responses for all model invocations in your account. Deleting a model invocation logging configuration can have security implications to your AI workloads.
- AWS CloudTrail Account Discovery
- Adversaries may attempt to get a listing of accounts on a system or within an environment. This information can help adversaries determine which accounts exist to aid in follow-on behavior.
- AWS CloudTrail Attempt To Leave Org
- Detects when an actor attempts to remove an AWS account from an Organization. Security configurations are often defined at the organizational level. Leaving the organization can disrupt or totally shut down these controls.
- AWS CloudTrail CloudWatch Logs
- CloudTrail supports sending data and management events to CloudWatch Logs. This setup can be used for real-time processing of all CloudTrail data events.
- AWS CloudTrail Log Encryption
- This policy validates that CloudTrail Logs are encrypted at rest with customer managed KMS key.
- AWS CloudTrail Log Validation
- This policy ensures that CloudTrail logs have file integrity validation enabled.
- AWS CloudTrail Management Events Enabled
- This policy ensures that at least one CloudTrail has management (control plane) operations logged.
- AWS CloudTrail Password Policy Discovery
- This detection looks for *AccountPasswordPolicy events in AWS CloudTrail logs. If these events occur in a short period of time from the same ARN, it could constitute Password Policy reconnaissance.
- AWS Cloudtrail Region Enabled
- Threat actors who successfully compromise a victim's AWS account, whether through stolen credentials, exposed access keys, exploited IAM misconfigurations, vulnerabilities in third-party applications, or the absence of Multi-Factor Authentication (MFA), can exploit unused regions as safe zones for malicious activities. These regions are often overlooked in monitoring and security setups, making them an attractive target for attackers to operate undetected.
- AWS CloudTrail Retention Lifecycle Too Short
- Detects when an S3 bucket containing CloudTrail logs has been modified to delete data after a short period of time.
- AWS CloudTrail S3 Bucket Access Logging
- This policy validates that the bucket receiving CloudTrail Logs is configured with S3 Access Logging. This audits all creation, modification, or deletion to CloudTrail audit logs.
- AWS CloudTrail S3 Bucket Public
- This policy validates that CloudTrail S3 buckets are not publicly accessible.
- AWS CloudTrail SES Check Identity Verifications
- AWS CloudTrail SES Check Send Quota
- Detect when someone checks how many emails can be delivered via SES
- AWS CloudTrail SES Check SES Sending Enabled
- Detect when a user inquires whether SES Sending is enabled.
- AWS CloudTrail SES Enumeration
- AWS CloudTrail SES List Identities
- AWS Compromised IAM Key Quarantine
- Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.
- AWS Config Service Created
- An AWS Config Recorder or Delivery Channel was created
- AWS Config Service Disabled
- An AWS Config Recorder or Delivery Channel was disabled or deleted
- AWS Console Login
- AWS Console Sign-In NOT PRECEDED BY Okta Redirect
- A user has logged into the AWS console without authenticating via Okta. This rule requires AWS SSO via Okta and both log sources configured.
- AWS Decrypt SSM Parameters
- Identify principles retrieving a high number of SSM Parameters of type 'SecretString'.
- AWS DNS Logs Deleted
- Detects when logs for a DNS Resolver have been removed.
- AWS EC2 Discovery Commands Executed
- Multiple different discovery commands were executed by the same EC2 instance.
- AWS EC2 Download Instance User Data
- An entity has accessed the user data scripts of multiple EC2 instances.
- AWS EC2 EBS Encryption Disabled
- Identifies disabling of default EBS encryption. Disabling default encryption does not change the encryption status of existing volumes.
- AWS EC2 Image Monitoring
- Checks CloudTrail for occurrences of EC2 Image Actions.
- AWS EC2 Launch Unusual EC2 Instances
- Detect when an actor deploys an EC2 instance with an unusual profile based on your business needs.
- AWS EC2 Manual Security Group Change
- An EC2 security group was manually updated without abiding by the organization's accepted processes. This rule expects organizations to either use the Console, CloudFormation, or Terraform, configurable in the rule's ALLOWED_USER_AGENTS.
- AWS EC2 Many Password Read Attempts
- An actor in AWS has made many attempts to retrieve EC2 passwords. It is typically not necessary to retrieve EC2 passwords more than a few times an hour.
- AWS EC2 Multi Instance Connect
- Detect when an attacker pushes an SSH public key to multiple EC2 instances.
- AWS EC2 Startup Script Change
- Detects changes to the EC2 instance startup script. The shell script will be executed as root/SYSTEM every time the specific instances are booted up.
- AWS EC2 Traffic Mirroring
- This rule captures multiple traffic mirroring events in AWS Cloudtrail.
- AWS EC2 Vulnerable XZ Image Launched
- Detecting EC2 instances launched with AMIs containing potentially vulnerable versions of XZ (CVE-2024-3094)
- AWS ECR Events
- An ECR event occurred outside of an expected account or region
- AWS IAM Access Key Compromise Detection
- This alert occurs when AWS has detected exposed credentials. It attaches a policy to deny certain actions, effectively quarantining those credentials, and is accompanied by a support case with instructions for detaching the policy.
- AWS IAM Group Read Only Events
- This rule captures multiple read/list events related to IAM group management in AWS Cloudtrail.
- AWS Macie Disabled/Updated
- Amazon Macie is a data security and data privacy service to discover and protect sensitive data. Security teams use Macie to detect open S3 Buckets that could have potentially sensitive data in it along with policy violations, such as missing Encryption. If an attacker disables Macie, it could potentially hide data exfiltration.
- AWS Modify Cloud Compute Infrastructure
- Detection when EC2 compute infrastructure is modified outside of expected automation methods.
- AWS Network ACL Overly Permissive Entry Created
- A Network ACL entry that allows access from anywhere was added.
- AWS Potential Backdoor Lambda Function Through Resource-Based Policy
- Identifies when a permission is added to a Lambda function, which could indicate a potential security risk.
- AWS Potentially Stolen Service Role
- A role was assumed by an AWS service, followed by a user within 24 hours. This could indicate a stolen or compromised AWS service role.
- AWS Privilege Escalation Via User Compromise
- AWS Public RDS Restore
- Detects the recovery of a new public database instance from a snapshot. It may be part of data exfiltration.
- AWS RDS Manual/Public Snapshot Created
- A manual snapshot of an RDS database was created. An attacker may use this to exfiltrate the DB contents to another account; use this as a correlation rule.
- AWS RDS Master Password Updated
- A sensitive database operation that should be performed carefully or rarely
- AWS RDS Snapshot Shared
- An RDS snapshot was shared with another account. This could be an indicator of exfiltration.
- AWS Resource Made Public
- Some AWS resource was made publicly accessible over the internet. Checks ECR, Elasticsearch, KMS, S3, S3 Glacier, SNS, SQS, and Secrets Manager.
- AWS S3 Bucket Policy Modified
- An S3 Bucket was modified.
- AWS S3 Copy Object with Client-Side Encryption
- This rule detects when objects are copied in an S3 bucket with client-side encryption. Such actions can be indicative of unauthorized data access or other suspicious activities.
- AWS S3 Delete Object Detection
- This rule detects when many objects are deleted from an S3 bucket. Such actions can be indicative of unauthorized data deletion or other suspicious activities.
- AWS S3 Delete Objects Detection
- This rule detects when multiple objects are deleted from an S3 bucket. Such actions can be indicative of unauthorized data deletion or other suspicious activities.
- AWS SAML Activity
- Identifies when SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
- AWS Secrets Manager Batch Retrieve Secrets
- An attacker attempted to retrieve a high number of Secrets Manager secrets by batch, through secretsmanager:BatchGetSecretValue (released Novemeber 2023). An attacker may attempt to retrieve a high number of secrets by batch, to avoid detection and generate fewer calls. Note that the batch size is limited to 20 secrets.
- AWS Secrets Manager Batch Retrieve Secrets Catch-All
- An attacker attempted to retrieve a high number of Secrets Manager secrets by batch, through secretsmanager:BatchGetSecretValue (released Novemeber 2023). An attacker may attempt to retrieve a high number of secrets by batch, to avoid detection and generate fewer calls. Note that the batch size is limited to 20 secrets. Although BatchGetSecretValue requires a list of secret IDs or a filter, an attacker may use a catch-all filter to retrieve all secrets by batch. This rule identifies BatchGetSecretValue events with a catch-all filter.
- AWS Secrets Manager Retrieve Secrets Multi-Region
- An attacker attempted to retrieve a high number of Secrets Manager secrets by batch, through secretsmanager:BatchGetSecretValue (released Novemeber 2023). An attacker may attempt to retrieve a high number of secrets by batch, to avoid detection and generate fewer calls. Note that the batch size is limited to 20 secrets. This rule identifies BatchGetSecretValue events for multiple regions in a short period of time.
- AWS SecurityHub Finding Evasion
- Detections modification of findings in SecurityHub
- AWS Snapshot Made Public
- An AWS storage snapshot was made public.
- AWS Software Discovery
- A user is obtaining a list of security software, configurations, defensive tools, and sensors that are in AWS.
- AWS SSM Distributed Command
- Detect an attacker utilizing AWS Systems Manager (SSM) to execute commands through SendCommand on multiple EC2 instances.
- AWS SSM Multiple Sessions
- Returns StartSession events by users who triggered more than 2 StartSession events over the past hour.
- AWS SSO Access Token Retrieved by Unauthenticated IP
- When using AWS in an enterprise environment, best practices dictate to use a single sign-on service for identity and access management. AWS SSO is a popular solution, integrating with third-party providers such as Okta and allowing to centrally manage roles and permissions in multiple AWS accounts.In this post, we demonstrate that AWS SSO is vulnerable by design to device code authentication phishing – just like any identity provider implementing OpenID Connect device code authentication. This technique was first demonstrated by Dr. Nestori Syynimaa for Azure AD. The feature provides a powerful phishing vector for attackers, rendering ineffective controls such as MFA (including Yubikeys) or IP allow-listing at the IdP level.
- AWS Trusted IPSet Modified
- Detects creation and updates of the list of trusted IPs used by GuardDuty and WAF. Potentially to disable security alerts against malicious IPs.
- AWS Unsuccessful MFA attempt
- Monitor application logs for suspicious events including repeated MFA failures that may indicate user's primary credentials have been compromised.
- AWS User API Key Created
- Detects AWS API key creation for a user by another user. Backdoored users can be used to obtain persistence in the AWS environment.
- AWS User Login Profile Created or Modified
- An attacker with iam:UpdateLoginProfile permission on other users can change the password used to login to the AWS console. May be legitimate account administration.
- AWS User Takeover Via Password Reset
- AWS VPC Flow Logs Removed
- Detects when logs for a VPC have been removed.
- AWS WAF Disassociation
- Detection to alert when a WAF disassociates from a source.
- AWS.Administrative.IAM.User.Created
- Identifies when an Administrative IAM user is creates. This could indicate a potential security breach.
- AWS.CloudTrail.UserAccessKeyAuth
- Brute Force By IP
- An actor user was denied login access more times than the configured threshold.
- Brute Force By User
- An actor user was denied login access more times than the configured threshold.
- CloudTrail EC2 StopInstances
- A CloudTrail instances were stopped. It makes further changes of instances possible
- CloudTrail Event Selectors Disabled
- A CloudTrail Trail was modified to exclude management events for 1 or more resource types.
- CloudTrail Password Spraying
- Detect password spraying account using a scheduled query
- CloudTrail Stopped
- A CloudTrail Trail was modified.
- CodeBuild Project made Public
- An AWS CodeBuild Project was made publicly accessible
- Detect Reconnaissance from IAM Users
- An IAM user has a high volume of access denied API calls.
- EC2 Network ACL Modified
- An EC2 Network ACL was modified.
- EC2 Network Gateway Modified
- An EC2 Network Gateway was modified.
- EC2 Route Table Modified
- An EC2 Route Table was modified.
- EC2 Secrets Manager Retrieve Secrets
- An attacker attempted to retrieve a high number of Secrets Manager secrets, through secretsmanager:GetSecretValue.
- EC2 Security Group Modified
- An EC2 Security Group was modified.
- EC2 VPC Modified
- An EC2 VPC was modified.
- ECR CRUD Actions
- Unauthorized ECR Create, Read, Update, or Delete event occurred.
- External Principal Accessing AWS Resources Via VPC Endpoint
- This rule detects when a principal from one AWS account accesses resources in a different AWS account using a VPC Endpoint. While cross-account access may be expected in some cases, it could also indicate unauthorized lateral movement between AWS accounts.
- Failed Root Console Login
- A Root console login failed.
- IAM Administrator Role Policy Attached
- An IAM role policy was attached with Administrator Access, which could indicate a potential security risk.
- IAM Assume Role Blocklist Ignored
- A user assumed a role that was explicitly blocklisted for manual user assumption.
- IAM Change
- A change occurred in the IAM configuration. This could be a resource being created, deleted, or modified. This is a high level view of changes, helfpul to indicate how dynamic a certain IAM environment is.
- IAM Entity Created Without CloudFormation
- An IAM Entity (Group, Policy, Role, or User) was created manually. IAM entities should be created in code to ensure that permissions are tracked and managed correctly.
- IAM Policy Modified
- An IAM Policy was changed.
- IAM Role Created
- An IAM role was created.
- IAM Role Policy Updated to Allow Internet Access
- An IAM role policy was updated to allow internet access, which could indicate a backdoor.
- IAM User Created
- An IAM user was created, which could indicate a new user creation or policy update.
- IAM User Policy Attached with Administrator Access
- An IAM user policy was attached with Administrator Access, which could indicate a potential security risk.
- Impossible Travel for Login Action
- A user has subsequent logins from two geographic locations that are very far apart
- KMS CMK Disabled or Deleted
- A KMS Customer Managed Key was disabled or scheduled for deletion. This could potentially lead to permanent loss of encrypted data.
- Lambda CRUD Actions
- Unauthorized lambda Create, Read, Update, or Delete event occurred.
- Lambda Update Function Code
- Identifies when the code of a Lambda function is updated, which could indicate a potential security risk.
- Lambda Update Function Configuration with Layers
- Identifies when a Lambda function configuration is updated with layers, which could indicate a potential security risk.
- Logins Without MFA
- A console login was made without multi-factor authentication.
- Logins Without SAML
- An AWS console login was made without SAML/SSO.
- Monitor Unauthorized API Calls
- An unauthorized AWS API call was made
- New AWS Account Created
- A new AWS account was created
- New IAM Credentials Updated
- A console password, access key, or user has been created.
- New User Account Created
- A new account was created
- RoleAssumes by Multiple Useragents
- RoleAssumes with multiple Useragents could indicate compromised credentials.
- Root Account Access Key Created
- An access key was created for the Root account
- Root Account Activity
- Root account activity was detected.
- Root Console Login
- The root account has been logged into.
- Root Password Changed
- Someone manually changed the Root console login password.
- S3 Access Via VPC Endpoint From External IP
- Detects S3 data access through VPC endpoints from external/public IP addresses, which could indicate data exfiltration attempts.This rule can be customized with the following overrides:- S3_DATA_ACCESS_OPERATIONS: List of S3 operations to monitor
- S3 Bucket Deleted
- A S3 Bucket, Policy, or Website was deleted
- Secret Exposed and not Quarantined
- The rule detects when a GitHub Secret Scan detects an exposed secret, which is not followed by the expected quarantine operation in AWS. When you make a repository public, or push changes to a public repository, GitHub always scans the code for secrets that match partner patterns. Public packages on the npm registry are also scanned. If secret scanning detects a potential secret, we notify the service provider who issued the secret. The service provider validates the string and then decides whether they should revoke the secret, issue a new secret, or contact you directly. Their action will depend on the associated risks to you or them.
- Sensitive API Calls Via VPC Endpoint
- Detects sensitive or unusual API calls that might indicate lateral movement, reconnaissance, or other malicious activities through VPC Endpoints. Only available for CloudTrail, EC2, KMS, S3, and Secrets Manager services.
- Sign In from Rogue State
- Detects when an entity signs in from a nation associated with cyber attacks
- StopInstance FOLLOWED BY ModifyInstanceAttributes
- Identifies when StopInstance and ModifyInstanceAttributes CloudTrail events occur in a short period of time. Since EC2 startup scripts cannot be modified without first stopping the instance, StopInstances should be a signal.
- Unused AWS Region
- CloudTrail logged non-read activity from a verboten AWS region.
- VPC Endpoint Access Denied
- Detects when access is denied due to VPC Endpoint policies, which could indicate attempted unauthorized access to AWS resources.
- AWS CloudWatch Log Encryption
- AWS automatically performs server-side encryption of logs, but you can encrypt with your own CMK to protect extra sensitive log data.
- AWS CloudWatch Logs Data Retention
- By default, logs are kept indefinitely and never expire. You can adjust the retention policy for each log group, keeping the indefinite retention, or choosing a specific retention period.
- Sensitive AWS CloudWatch Log Encryption
- AWS automatically performs server-side encryption of logs, but you can encrypt with your own CMK to protect extra sensitive log data.
- AWS Config Global Resources
- You can have AWS Config record supported types of global resources, such as IAM users, groups, roles, and customer managed policies.
- AWS Config Recording Status
- This policy ensures that the config recorder is operational and capturing changes to your account without error.
- AWS Config Records All Resource Types
- This policy ensurers that you have a comprehensive configuration audit in place for all resource types in AWS.
- AWS Config Status
- This policy ensures that the config recorder is operational and capturing changes to your account.
- AWS DynamoDB Table Autoscaling
- DynamoDB Auto Scaling can dynamically adjust provisioned throughput capacity in response to traffic patterns. This enables a table to increase its provisioned read and write capacity to handle sudden increases in traffic
- AWS DynamoDB Table Autoscaling Configuration
- DynamoDB Auto Scaling can dynamically adjust provisioned throughput capacity in response to traffic patterns. This enables a table to increase its provisioned read and write capacity to handle sudden increases in traffic
- AWS DynamoDB Table TTL
- This policy validates that all DynamoDB tables have a TTL field configured.
- AWS AMI Sharing
- This policy ensures that AMIs you have created are not configured to allow public access, which could result in accidental data loss. AMI's that you use but do not own are not evaluated by this policy.
- AWS CDE EC2 Volume Encryption
- This policy ensures that all EC2 volumes that contain CDE are encrypted. Be sure to configure CDE definitions before enabling this policy.
- AWS EC2 AMI Approved Host
- Checks that AWS EC2 AMI's are only launched on approved dedicated hosts.
- AWS EC2 AMI Approved Instance Type
- This policy ensures that the EC2 instance is running with an instance type approved for its AMI.
- AWS EC2 AMI Approved Tenancy
- This policy ensures that the EC2 instance was launched with a tenancy approved for its AMI.
- AWS EC2 Instance Approved AMI
- This policy ensures the given EC2 instance is running an AMI from the approved list of AMI's.
- AWS EC2 Instance Approved Host
- This policy ensures the given EC2 Instance is running on an approved dedicated host.
- AWS EC2 Instance Approved Instance Type
- This policy ensures that the EC2 instance is running on one of the approved instance types.
- AWS EC2 Instance Approved Tenancy
- This policy ensures the given EC2 Instance is running with an approved tenancy option. The possible tenancy options are dedicated, host, and default.
- AWS EC2 Instance Approved VPC
- This policy ensures that the given EC2 Instance is running in an approved VPC.
- AWS EC2 Instance Detailed Monitoring
- This policy ensures that the AWS Instance has Detailed Monitoring Enabled
- AWS EC2 Instance EBS Optimization
- This policy ensures EBS optimization is enabled for the given EC2 instance, if applicable.
- AWS EC2 Volume Encryption
- You can encrypt both the boot and data volumes of an EC2 instance.
- AWS EC2 Volume Snapshot Encryption
- You can encrypt the snapshot of an EC2 volume to protect against accidental data loss
- AWS Network ACL Restricts Inbound Traffic
- This policy validates that Network ACLs restrict inbound traffic in some way.
- AWS Network ACL Restricts Insecure Protocols
- This policy validates that Network ACLs block the usage of ports typically associated with insecure or unencrypted protocols.
- AWS Network ACL Restricts Outbound Traffic
- This policy validates that Network ACLs have some restrictions on outbound traffic.
- AWS Network ACL Restricts SSH
- SSH access should only be granted from protected network CIDR ranges.
- AWS Resource Minimum Tags
- This policy ensures that applicable resources have a minimum number of tags set.
- AWS Resource Required Tags
- This policy ensures that AWS resources have specific tags, dependent on their resource type.
- AWS Security Group - Only DMZ Publicly Accessible
- This policy validates that only Security Groups designated as DMZs allow inbound traffic from public IP space. This helps ensure no traffic is bypassing the DMZ.
- AWS Security Group Administrative Ingress
- This policy validates that AWS Security Groups don't allow unrestricted inbound traffic on port 3389 or 22, ports commonly used for the remote access protocols RDP and SSH respectively.
- AWS Security Group Restricts Access To CDE
- This policy validates that are considered part of the PCI CDE do not allow any access from public IP space.
- AWS Security Group Restricts Inbound Traffic
- This policy validates that Security Groups have some restrictions on inbound traffic.
- AWS Security Group Restricts Inter-SG Traffic
- This policy validates that Security Groups have restrictions on inter Security Group traffic. Administrators may assume there is an implicit level of trust between Security Groups in the same account, but this is not always a good assumption in cases one Security Group contains far more sensitive data that another.
- AWS Security Group Restricts Outbound Traffic
- This policy validates that Security Groups have some restrictions on outbound traffic.
- AWS Security Group Restricts Traffic Leaving CDE
- This policy validates that there are restrictions on what type of traffic may leave Security Groups that are considered with the scope of the PCI CDE. These restrictions help ensure that cardholder data does not leave the CDE.
- AWS Security Group Tightly Restricts Inbound Traffic
- This policy validates that Security Groups have restrictive permission sets that both limit the total number of open ports, as well as limiting ports typically associated with insecure protocols.
- AWS Security Group Tightly Restricts Outbound Traffic
- This policy validates that Security Groups have restrictive controls on outbound traffic.
- AWS VPC Default Network ACL Restricts All Traffic
- This policy validates that the default Network ACL for a given AWS VPC is restricting all inbound and outbound traffic.
- AWS VPC Default Security Group Restrictions
- This policy validates that the default Security Group for a given AWS VPC is restricting all inbound and outbound traffic.
- AWS VPC Flow Logs
- This policy validates that AWS VPCs (Virtual Private Clouds) have network flow logging enabled.
- EKS Anonymous API Access Detected
- This rule detects anonymous API requests made to the Kubernetes API server. In production environments, anonymous access should be disabled to prevent unauthorized access to the API server.
- EKS Audit Log based single sourceIP is generating multiple 403s
- This detection identifies if a public sourceIP is generating multiple 403s with the Kubernetes API server.
- EKS Audit Log Reporting system Namespace is Used From A Public IP
- This detection identifies if an activity is recorded in the Kubernetes audit log where the user:username attribute begins with "system:" or "eks:" and the requests originating IP Address is a Public IP Address
- IOC Activity in K8 Control Plane
- This detection monitors for any kubernetes API Request originating from an Indicator of Compromise.
- Kubernetes Cron Job Created or Modified
- This detection monitor for any modifications or creations of a cron job. Attackers may create or modify an existing scheduled job in order to achieve cluster persistence.
- Kubernetes Pod Created in Pre-Configured or Default Name Spaces
- This detection monitors for any pod created in pre-configured or default namespaces. Only Cluster Admins should be creating pods in the kube-system namespace, and it is best practice not to run any cluster critical infrastructure here. The kube-public namespace is intended to be readable by unauthenticated users. The default namespace is shipped with the cluster and it is best practice not to deploy production workloads here. These namespaces may be used to evade defenses or hide attacker infrastructure.
- New Admission Controller Created
- This detection monitors for a new admission controller being created in the cluster. Admission controllers allows an attack to intercept all API requests made within a cluster, allowing for enumeration of resources and common actions. This can be a very powerful tool to understand where to pivot to next.
- New DaemonSet Deployed to Kubernetes
- This detection monitors for a new DaemonSet deployed to a kubernetes cluster. A daemonset is a workload that guarantees the presence of exactly one instance of a specific pod on every node in the cluster. This can be a very powerful tool for establishing peristence.
- Pod attached to the Node Host Network
- This detection monitor for the creation of pods which are attached to the host's network. This allows a pod to listen to all network traffic for all deployed computer on that particular node and communicate with other compute on the network namespace. Attackers can use this to capture secrets passed in arguments or connections.
- Pod Created or Modified Using the Host IPC Namespace
- This detection monitors for any pod creation or modification using the host IPC Namespace. Deploying pods in the Host IPC Namespace, breaks isolation between the pod and the underlying host meaning the pod has direct access to the same IPC objects and communications channels as the host system.
- Pod Created or Modified Using the Host PID Namespace
- This detection monitors for any pod creation or modification using the host PID namespace. The Host PID namespace enables a pod and its containers to have direct access and share the same view as of the host���s processes. This can offer a powerful escape hatch to the underlying host.
- Pod Created with Overly Permissive Linux Capabilities
- This detection monitors for a pod created with overly permissive linux capabilities. Excessive pod permissions and capabilities can be a launch point for privilege escalation or container breakout.
- Pod creation or modification to a Host Path Volume Mount
- This detection monitors for pod creation with a hostPath volume mount. The attachment to a node's volume can allow for privilege escalation through underlying vulnerabilities or it can open up possibilities for data exfiltration or unauthorized file access. It is very rare to see this being a pod requirement.
- Privileged Pod Created
- This detection monitors for a privileged pod is created either by default or with permissions to run as root. These particular pods have full access to the hosts namespace and devices, ability to exploit the kernel, have dangerous linux capabilities, and can be a powerful launching point for further attacks.
- Secret Enumeration by a User
- This detection monitors for a large number of secrets requests by a single user. This could potentially indicate secret enumeration, which can potentially enable lateral or vertical movement and unauthorized access to critical resources.
- Unauthenticated Kubernetes API Request
- This detection monitors for any unauthenticated kubernetes api request. Unauthenticated Requests are performed by the anonymous user and have unfederated access to the cluster.
- Unauthorized Kubernetes Pod Execution
- This detection monitors for any pod execution in a kubernetes cluster. Pod execution should never be done in a production cluster, and can indicate a user performing unauthorized actions.
- AWS Application Load Balancer Web ACL
- This policy validates that all application load balancers have an associated Web ACl to enforce protections against various web attacks.
- AWS ELB SSL Policies
- Ensures that deprecated TLS versions are not supported in internet-facing load balancers
- AWS Enforces SSL Policies
- This policy validates that ELBV2 load balancer listeners are using an SSL policy.
- AWS GuardDuty Critical Severity Finding
- A critical-severity GuardDuty finding has been identified.
- AWS GuardDuty Enabled
- GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior.
- AWS GuardDuty High Severity Finding
- A high-severity GuardDuty finding has been identified.
- AWS GuardDuty Low Severity Finding
- A low-severity GuardDuty finding has been identified.
- AWS GuardDuty Master Account
- Ensure that all GuardDuty logs are sending into a single Master account. This is a best practice for centralizing detection logic and useful data during an investigation.
- AWS GuardDuty Medium Severity Finding
- A medium-severity GuardDuty finding has been identified.
- AWS Access Key Rotation
- This policy validates that AWS IAM account access keys are rotated every 90 days. Rotating access keys will reduce the window of opportunity for an access key that is associated with a compromised or terminated account to be used.
- AWS Access Keys At Account Creation
- This policy validates that AWS IAM user accounts do not have access keys that were created during account creation. This results in excess keys being generated, and unnecessary management work in auditing and rotating these keys.
- AWS CloudTrail Least Privilege Access
- Users with permissions to disable or reconfigure CloudTrail should be limited.
- AWS IAM Group Users
- This Policy ensures that all IAM groups have at least one IAM user. If they are vacant, they should be deleted.
- AWS IAM Password Unused
- This policy validates IAM users with console passwords have logged in within the past 90 days.
- AWS IAM Policy Administrative Privileges
- This policy validates that there are no IAM policies that grant full administrative privileges to IAM users or groups.
- AWS IAM Policy Assigned to User
- This policy validates that there are no IAM policies assigned directly to users. Best practice suggests assigning to an IAM group and placing users within that group.
- AWS IAM Policy Blocklist
- This detects the usage of highly permissive IAM Policies that should only be assigned to a small number of users, roles, or groups.
- AWS IAM Policy Does Not Grant Any Administrative Access
- This policy validates that no IAM policies grant admin access. This should be combined with suppressions on the legitimate IAM admin policies in your account so that it only fires when new and unexpected policies granting admin access are created.
- AWS IAM Policy Does Not Grant Network Admin Access
- This policy validates that no IAM policies grant admin privileges on network resources. This should be used in conjunction with suppressions for the legitimate network admin policies in your account.
- AWS IAM Policy Role Mapping
- This policy validates that policies that have been explicitly configured to be set to certain roles are still attached to those roles.
- AWS IAM Resource Does Not Have Inline Policy
- This policy validates that no IAM entities have inline policies assigned. Inline policies are more difficult to administer and audit, and may lead to access that lasts longer than intended.
- AWS IAM Role Grants (permission) to Non-organizational Account
- This policy validates that IAM roles that grant the (specified) permission do not allow accounts outside the organization to assume them.
- AWS IAM Role Restricts Usage
- This policy validates that IAM roles in the account are restrictive in what entities may assume them. This can help prevent malicious actors from assuming roles they should not be assuming.
- AWS IAM Role Trust Relationship for GitHub Actions
- This policy ensures that IAM roles used with GitHub Actions are securely configured to prevent unauthorized access to AWS resources. It validates trust relationships by checking for proper audience (aud) restrictions, ensuring it is set to sts.amazonaws.com, and subject (sub) conditions, confirming they are scoped to specific repositories or environments. Misconfigurations, such as overly permissive wildcards or missing conditions, can allow unauthorized repositories to assume roles, leading to potential data breaches or compliance violations. By enforcing these checks, the policy mitigates risks of exploitation, enhances security posture, and protects critical AWS resources from external threats.
- AWS IAM User MFA
- This policy validates that all AWS IAM users with access to the AWS Console have Multi-Factor Authentication (MFA) enabled.
- AWS IAM User Not In Conflicting Groups
- This policy validates that IAM users are not in IAM groups that are considered mutually exclusive. For example, in some workflows developers are responsible for dev environments and sysadmins are responsible for prod environments. In this situation no (or very few) users should be in both sysadmin and developer groups. This is in following with the principle of least privilege.
- AWS Resource Minimum Tags
- This policy ensures that applicable resources have a minimum number of tags set.
- AWS Resource Required Tags
- This policy ensures that AWS resources have specific tags, dependent on their resource type.
- AWS Root Account Access Keys
- This policy validates that no programmatic access keys exist for the root account.
- AWS Root Account Hardware MFA
- This policy validates that a hardware MFA device is in use for access to the root account.
- AWS Root Account MFA
- This policy validates that Multi Factor Authentication (MFA) is required for access to the root account.
- AWS Unused Access Key
- This policy validates that IAM user access keys are used at least once every 90 days.
- IAM Inline Policy Network Admin
- This policy validates that IAM entities (Groups, Roles, and Users) do not have inline policies attached that grant network admin privileges. Inline policies are more difficult to track and audit than managed policies, and can lead to persistent unexpected access.
- AWS KMS CMK Key Rotation
- This policy validates that customer master keys (CMKs) have automatic key rotation enabled.
- AWS KMS Key Restricts Usage
- This policy validates that KMS Keys restrict what entities can use them and how. This is to ensure that encryption keys are limited in who can use them in order to prevent unapproved decryption.
- AWS Lambda Public Access
- This policy ensures that the function policy attached to the Lambda resource prohibits public access
- AWS Password Policy Complexity Guidelines
- This policy validates that the account password policy enforces the recommended password complexity requirements.
- AWS Password Policy Password Age Limit
- This policy validates that the account password policy enforces a maximum password age of 90 days or less.
- AWS Password Policy Password Reuse
- This policy validates that the account password policy prevents users from re-using previous passwords, and prevents password reuse for 24 or more prior passwords.
- AWS RDS Instance Backup
- This Policy ensures that RDS Instances have Backups enabled. Backups are an important aspect of disaster recovery that can protect sensitive data from destruction.
- AWS RDS Instance Encryption
- This policy validates that RDS instances have encryption enabled.
- AWS RDS Instance Has Acceptable Backup Retention Period
- This policy validates that RDS instances are configured with a backup retention period that is acceptable to company policy. This ensures for both compliance and security reasons that records are kept for a minimum period of time, and for compliance and performance reasons that records are not kept indefinitely.
- AWS RDS Instance High Availability
- This Policy ensures that RDS Instances have are running in High Availability mode to provide redundancy in the event of an operational failure. For Aurora, storage is replicated across all the Availability Zones and doesn't require this setting.
- AWS RDS Instance Minor Version Upgrades
- If you want Amazon RDS to upgrade the DB engine version of a database automatically, you can enable auto minor version upgrades for the database.
- AWS RDS Instance Public Access
- This Policy checks that an RDS Instance is not accessible from the public internet.
- AWS RDS Instance Snapshot Public Access
- This policy validates that RDS Instance snapshots are not publicly restorable. This would allow anyone to restore an old version of your database and have full access to its contents.
- AWS Redshift Cluster Encryption
- This policy validates that Redshift Clusters have encryption enabled.
- AWS Redshift Cluster Has Acceptable Snapshot Retention Period
- This policy validates that Redshift Cluster snapshot retention periods are set to an appropriate time. This ensures that records are kept long enough for compliance and security reasons, but no too long for compliance and performance reasons.
- AWS Redshift Cluster Logging
- This policy validates that Redshift Cluster have logging enabled. This includes audit logs.
- AWS Redshift Cluster Maintenance Window
- This policy validates that Redshift Clusters have the correct preferred maintenance window configured.
- AWS Redshift Cluster Snapshot Retention
- This policy validates that Redshift Clusters have sufficient snapshot retention periods, so that snapshots are not lost before they are needed.
- AWS Redshift Cluster Version Upgrade
- This policy validates that Redshift Clusters automatically perform upgrades during scheduled maintenance windows.
- AWS S3 Bucket Action Restrictions
- Ensures that the S3 bucket policy does not allow any action on the bucket, in accordance with the principal of least privilege.
- AWS S3 Bucket Encryption
- Ensures that the S3 bucket has encryption enabled.
- AWS S3 Bucket Lifecycle Configuration
- Verifies that the S3 Bucket Object Lifecycle configuration expires data within 90 and 365 days.
- AWS S3 Bucket Logging
- Ensures that a logging policy is set for the S3 bucket.
- AWS S3 Bucket MFA Delete
- Ensures that MFA delete is enabled for a bucket so that all objects can only be deleted by users authenticated with MFA.
- AWS S3 Bucket Name DNS Compliance
- This policy validates that the AWS S3 bucket name is DNS compliant.
- AWS S3 Bucket Object Lock Configured
- This policy validates that S3 buckets have an Object Lock configuration enabled. This should be used with specific suppression lists to ensure it is applied only to appropriate S3 buckets, such as those containing CloudTrail or other auditable records.
- AWS S3 Bucket Policy Allow With Not Principal
- Prevents the use of a 'Not' principal in conjunction with an allow effect in an S3 bucket policy, which would allow global access for the resource besides the principals specified.
- AWS S3 Bucket Principal Restrictions
- This policy validates that S3 Bucket access policies do not allow all users (Principal:"*") for a given action on the bucket, in accordance with the principle of least privilege.
- AWS S3 Bucket Public Access Block
- Ensures that a Public Access Block Configuration is set for the given S3 bucket.
- AWS S3 Bucket Public Read
- Ensures that the S3 bucket is not publicly readable.
- AWS S3 Bucket Public Write
- Ensures that the S3 bucket is not publicly writeable.
- AWS S3 Bucket Secure Access
- Ensures access to S3 buckets is forced to use a secure (HTTPS) connection.
- AWS S3 Bucket Versioning
- Checks that object versioning is enabled in the S3 bucket.
- S3 Bucket Policy Confused Deputy Protection for Service Principals
- Ensures that S3 bucket policies with service principals include conditions to prevent the confused deputy problem.
- AWS S3 Access Error
- Checks for errors during S3 Object access. This could be due to insufficient access permissions, non-existent buckets, or other reasons.
- AWS S3 Access IP Allowlist
- Checks that the remote IP accessing the S3 bucket is in the IP allowlist.
- AWS S3 Insecure Access
- Checks if HTTP (unencrypted) was used to access objects in an S3 bucket, as opposed to HTTPS (encrypted).
- AWS S3 Unauthenticated Access
- Checks for S3 access attempts where the requester is not an authenticated AWS user.
- AWS S3 Unknown Requester
- Validates that proper IAM entities are accessing sensitive data buckets.
- Decoy DynamoDB Accessed
- Actor accessed Decoy DynamoDB
- Decoy IAM Assumed
- Actor assumed decoy IAM role
- Decoy S3 Accessed
- Actor accessed S3 Manager decoy secret
- Decoy Secret Accessed
- Actor accessed Secrets Manager decoy secret
- Decoy Systems Manager Parameter Accessed
- Actor accessed Decoy Systems Manager parameter
- AWS DNS Crypto Domain
- Identifies clients that may be performing DNS lookups associated with common currency mining pools.
- DNS Base64 Encoded Query
- Detects DNS queries with Base64 encoded subdomains, which could indicate an attempt to obfuscate data exfil.
- VPC DNS Tunneling
- Detect dns tunneling traffic using a scheduled query
- Anomalous VPC Traffic to Destination Port
- Look at which VPC hosts have been sending a lot of traffic over the past hour
- AWS VPC Healthy Log Status
- Checks for the log status
SKIPDATA, which indicates that data was lost either to an internal server error or due to capacity constraints.
- Checks for the log status
- VPC Flow Logs Inbound Port Allowlist
- VPC Flow Logs observed inbound traffic violating the port allowlist.
- VPC Flow Logs Inbound Port Blocklist
- VPC Flow Logs observed inbound traffic violating the port blocklist.
- VPC Flow Logs Unapproved Outbound DNS Traffic
- Alerts if outbound DNS traffic is detected to a non-approved DNS server. DNS is often used as a means to exfiltrate data or perform command and control for compromised hosts. All DNS traffic should be routed through internal DNS servers or trusted 3rd parties.
- VPC Flow Port Scanning
- Instances of a srcAddr communicating with multiple ports on a dstAddr could indicate port scanning activity.
- Wiz Issue Followed By SSH to EC2 Instance
- Wiz detected a security issue with an EC2 instance followed by an SSH connection to the instance. This sequence could indicate a potential security breach.
- AWS WAF Has XSS Predicate
- This policy validates that all WAF's have at least one rule with a predicate matching on and blocking XSS attacks.
- AWS WAF Logging Configured
- Ensures that AWS WAF logging is enabled and that the logs are being sent to a valid destination (S3, CloudWatch, or Kinesis Firehose). Without logging, visibility into WAF activity is severely limited, increasing the risk of undetected attacks.
- AWS WAF Rule Ordering
- This policy validates that all WAF's have the correct rule ordering. Incorrect rule ordering could lead to less restrictive rules being matched and allowing traffic through before more restrictive rules that should have blocked the traffic.
- AWS WAF WebACL Has Associated Resources
- This policy ensures that AWS WAF WebACLs are associated with at least one resource (ALB, CloudFront Distribution, or API Gateway). If a WebACL is not associated with any resources, it is inactive and not providing any protection.