This repository was archived by the owner on Sep 16, 2026. It is now read-only.
forked from panther-labs/panther-analysis
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdetection-coverage.json
More file actions
6961 lines (6961 loc) · 289 KB
/
Copy pathdetection-coverage.json
File metadata and controls
6961 lines (6961 loc) · 289 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
[
{
"AnalysisType": "Scheduled Rule",
"Description": "Detects 1Password Logins from IP addresses not found in CrowdStrike's AIP list. May indicate unmanaged device being used, or faulty CrowdStrike Sensor.",
"DisplayName": "1Password Login From CrowdStrike Unmanaged Device",
"LogTypes": [
"Crowdstrike.AIDMaster",
"OnePassword.SignInAttempt"
],
"YAMLPath": "queries/crowdstrike_queries/onepassword_login_from_crowdstrike_unmanaged_device.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "Looks for OnePassword Logins from IP Addresses that aren't seen in CrowdStrike's AIP List.",
"DisplayName": "1Password Login From CrowdStrike Unmanaged Device Query",
"LogTypes": [
"Crowdstrike.AIDMaster",
"OnePassword.SignInAttempt"
],
"YAMLPath": "queries/crowdstrike_queries/onepass_login_from_crowdstrike_unmanaged_device_query.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "Looks for OnePassword Logins from IP Addresses that aren't seen in CrowdStrike's AIP List. (crowdstrike_fdrevent table)",
"DisplayName": "1Password Login From CrowdStrike Unmanaged Device Query (crowdstrike_fdrevent table)",
"LogTypes": [
"Crowdstrike.FDREvent",
"OnePassword.SignInAttempt"
],
"YAMLPath": "queries/onepassword_queries/onepass_login_from_crowdstrike_unmanaged_device_FDREvent.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detects vulnerable versions of XZ and liblzma on Linux and MacOS using Osquery logs. Versions 5.6.0 and 5.6.1 of xz and liblzma are most likely vulnerable to backdoor exploit. Vuln management pack must be enabled: https://github.com/osquery/osquery/blob/master/packs/vuln-management.conf",
"DisplayName": "A backdoored version of XZ or liblzma is vulnerable to CVE-2024-3094",
"LogTypes": [
"Osquery.Differential"
],
"YAMLPath": "rules/osquery_rules/osquery_linux_mac_vulnerable_xz_liblzma.yml"
},
{
"AnalysisType": "Rule",
"Description": "A CloudTrail Trail was created, updated, or enabled.",
"DisplayName": "A CloudTrail Was Created or Updated",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "A system has been logged into from a non approved IP space.",
"DisplayName": "A Login from Outside the Corporate Office",
"LogTypes": [
"Osquery.Differential"
],
"YAMLPath": "rules/osquery_rules/osquery_linux_logins_non_office.yml"
},
{
"AnalysisType": "Rule",
"Description": "An unusually long-lived Teleport certificate was created",
"DisplayName": "A long-lived cert was created",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_long_lived_certs.yml"
},
{
"AnalysisType": "Rule",
"Description": "A SAML connector was created or modified",
"DisplayName": "A SAML Connector was created or modified",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_saml_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "A Teleport Lock was created",
"DisplayName": "A Teleport Lock was created",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_lock_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "A Teleport Role was modified or created",
"DisplayName": "A Teleport Role was modified or created",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_role_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "A user authenticated with SAML, but from an unknown company domain",
"DisplayName": "A user authenticated with SAML, but from an unknown company domain",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_saml_login_not_company_domain.yml"
},
{
"AnalysisType": "Rule",
"Description": "A User from the company domain(s) Logged in without SAML",
"DisplayName": "A User from the company domain(s) Logged in without SAML",
"LogTypes": [
"Gravitational.TeleportAudit"
],
"YAMLPath": "rules/gravitational_teleport_rules/teleport_company_domain_login_without_saml.yml"
},
{
"AnalysisType": "Rule",
"Description": "A Panther user role has been created that contains admin level permissions.",
"DisplayName": "A User Role with Sensitive Permissions has been Created",
"LogTypes": [
"Panther.Audit"
],
"YAMLPath": "rules/panther_audit_rules/panther_sensitive_role_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "A Panther user's role has been modified. This could mean password, email, or role has changed for the user.",
"DisplayName": "A User's Panther Account was Modified",
"LogTypes": [
"Panther.Audit"
],
"YAMLPath": "rules/panther_audit_rules/panther_user_modified.yml"
},
{
"AnalysisType": "Rule",
"Description": "An account wide security configuration was changed.",
"DisplayName": "Account Security Configuration Changed",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_security_configuration_change.yml"
},
{
"AnalysisType": "Rule",
"Description": "An action was performed by Netskope personnel.",
"DisplayName": "Action Performed by Netskope Personnel",
"LogTypes": [
"Netskope.Audit"
],
"YAMLPath": "rules/netskope_rules/netskope_personnel_action.yml"
},
{
"AnalysisType": "Rule",
"Description": "An admin was logged out because of successive login failures.",
"DisplayName": "Admin logged out because of successive login failures",
"LogTypes": [
"Netskope.Audit"
],
"YAMLPath": "rules/netskope_rules/netskope_admin_logged_out.yml"
},
{
"AnalysisType": "Rule",
"Description": "Assigning an admin role manually could be a sign of privilege escalation",
"DisplayName": "Admin Role Assigned",
"LogTypes": [
"Asana.Audit",
"Atlassian.Audit",
"GCP.AuditLog",
"GSuite.Reports",
"GitHub.Audit",
"OneLogin.Events",
"Zendesk.Audit"
],
"YAMLPath": "rules/standard_rules/admin_assigned.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Amazon Machine Image (AMI) was modified to allow it to be launched by anyone. Any sensitive configuration or application data stored in the AMI's block devices is at risk.",
"DisplayName": "Amazon Machine Image (AMI) Modified to Allow Public Access",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_ami_modified_for_public_access.yml"
},
{
"AnalysisType": "Rule",
"Description": "An administrator account was created, deleted, or modified.",
"DisplayName": "An administrator account was created, deleted, or modified.",
"LogTypes": [
"Netskope.Audit"
],
"YAMLPath": "rules/netskope_rules/netskope_admin_user_change.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "ARNs with a high Access Denied error rate could indicate an error or compromised credentials attempting to perform reconnaissance.",
"DisplayName": "Anomalous AccessDenied Requests",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "queries/aws_queries/anomalous_access_denied_query.yml"
},
{
"AnalysisType": "Saved Query",
"Description": "Look at which VPC hosts have been sending a lot of traffic over the past hour",
"DisplayName": "Anomalous VPC Traffic to Destination Port",
"LogTypes": [
"AWS.VPCFlow"
],
"YAMLPath": "queries/aws_queries/anomalous_vpc_traffic_to_dest_port_query.yml"
},
{
"AnalysisType": "Rule",
"Description": "",
"DisplayName": "AppOmni Alert Passthrough",
"LogTypes": [
"AppOmni.Alerts"
],
"YAMLPath": "rules/appomni_rules/appomni_alert_passthrough.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana service account was created by someone in your organization.",
"DisplayName": "Asana Service Account Created",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_service_account_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana team's privacy setting was changed to public to the organization (not public to internet)",
"DisplayName": "Asana Team Privacy Public",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_team_privacy_public.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana workspace's default session duration (how often users need to re-authenticate) has been changed to never.",
"DisplayName": "Asana Workspace Default Session Duration Never",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_default_session_duration_never.yml"
},
{
"AnalysisType": "Rule",
"Description": "A new email domain has been added to an Asana workspace. Reviewer should validate that the new domain is a part of the organization.",
"DisplayName": "Asana Workspace Email Domain Added",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_email_domain_added.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana Workspace Form Link is a unique URL that allows you to create a task directly within a specific Workspace or Project in Asana, using a web form. Disabling authentication requirements may allow unauthorized users to create tasks.",
"DisplayName": "Asana Workspace Form Link Auth Requirement Disabled",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_form_link_auth_requirement_disabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "Typically inviting guests to Asana is permitted by few users. Enabling anyone to invite guests can potentially lead to unauthorized users gaining access to Asana.",
"DisplayName": "Asana Workspace Guest Invite Permissions Anyone",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_guest_invite_permissions_anyone.yml"
},
{
"AnalysisType": "Rule",
"Description": "Admin role was granted to the user who previously did not have admin permissions",
"DisplayName": "Asana Workspace New Admin",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_new_admin.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana user started an org export.",
"DisplayName": "Asana Workspace Org Export",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_org_export.yml"
},
{
"AnalysisType": "Rule",
"Description": "An asana user made your organization's password requirements less strict.",
"DisplayName": "Asana Workspace Password Requirements Simple",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_password_requirements_simple.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana user turned off app approval requirements for an application type for your organization.",
"DisplayName": "Asana Workspace Require App Approvals Disabled",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_require_app_approvals_disabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Asana user made SAML optional for your organization.",
"DisplayName": "Asana Workspace SAML Optional",
"LogTypes": [
"Asana.Audit"
],
"YAMLPath": "rules/asana_rules/asana_workspace_saml_optional.yml"
},
{
"AnalysisType": "Rule",
"Description": "Reports when an Atlassian user logs in (impersonates) another user.",
"DisplayName": "Atlassian admin impersonated another user",
"LogTypes": [
"Atlassian.Audit"
],
"YAMLPath": "rules/atlassian_rules/user_logged_in_as_user.yml"
},
{
"AnalysisType": "Rule",
"Description": "Okta has determined that the cross-origin authentication feature in Customer Identity Cloud (CIC) is prone to being targeted by threat actors orchestrating credential-stuffing attacks. Okta has observed suspicious activity that started on April 15, 2024. Review tenant logs for unexpected fcoa, scoa, and pwd_leak events.",
"DisplayName": "Auth0 CIC Credential Stuffing",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_cic_credential_stuffing.yml"
},
{
"AnalysisType": "Saved Query",
"Description": "Okta has determined that the cross-origin authentication feature in Customer Identity Cloud (CIC) is prone to being targeted by threat actors orchestrating credential-stuffing attacks. Okta has observed suspicious activity that started on April 15, 2024. Review tenant logs for unexpected fcoa, scoa, and pwd_leak events. https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks",
"DisplayName": "Auth0 CIC Credential Stuffing Query",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "queries/auth0_queries/auth0_cic_credential_stuffing_query.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User created a role in your organization's tenant.",
"DisplayName": "Auth0 Custom Role Created",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_custom_role_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 integration was installed from the auth0 action library.",
"DisplayName": "Auth0 Integration Installed",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_integration_installed.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 user enabled an mfa factor in your organization's mfa settings.",
"DisplayName": "Auth0 mfa factor enabled",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_mfa_factor_setting_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User disabled MFA for your organization's tenant.",
"DisplayName": "Auth0 MFA Policy Disabled",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_mfa_policy_disabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User enabled MFA Policy for your organization's tenant.",
"DisplayName": "Auth0 MFA Policy Enabled",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_mfa_policy_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User disabled the mfa risk assessment setting for your organization's tenant.",
"DisplayName": "Auth0 MFA Risk Assessment Disabled",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_mfa_risk_assessment_disabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User enabled the mfa risk assessment setting for your organization's tenant.",
"DisplayName": "Auth0 MFA Risk Assessment Enabled",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_mfa_risk_assessment_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Auth0 User updated a post login action flow for your organization's tenant.",
"DisplayName": "Auth0 Post Login Action Flow Updated",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_post_login_action_flow.yml"
},
{
"AnalysisType": "Rule",
"Description": "",
"DisplayName": "Auth0 User Invitation Created",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_user_invitation_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "User accepted invitation from Auth0 member to join an Auth0 tenant.",
"DisplayName": "Auth0 User Joined Tenant",
"LogTypes": [
"Auth0.Events"
],
"YAMLPath": "rules/auth0_rules/auth0_user_joined_tenant.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that AWS IAM account access keys are rotated every 90 days. Rotating access keys will reduce the window of opportunity for an access key that is associated with a compromised or terminated account to be used.",
"DisplayName": "AWS Access Key Rotation",
"LogTypes": [
"AWS.IAM.RootUser",
"AWS.IAM.User"
],
"YAMLPath": "policies/aws_iam_policies/aws_access_key_rotation.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that AWS IAM user accounts do not have access keys that were created during account creation. This results in excess keys being generated, and unnecessary management work in auditing and rotating these keys.",
"DisplayName": "AWS Access Keys At Account Creation",
"LogTypes": [
"AWS.IAM.RootUser",
"AWS.IAM.User"
],
"YAMLPath": "policies/aws_iam_policies/aws_access_keys_at_account_creation.yml"
},
{
"AnalysisType": "Policy",
"Description": "When a certificate is 60 days away from expiration, ACM automatically attempts to renew it every hour.",
"DisplayName": "AWS ACM Certificate Expiration",
"LogTypes": [
"AWS.ACM.Certificate"
],
"YAMLPath": "policies/aws_acm_policies/aws_acm_certificate_expiration.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy checks if an ACM certificate renewal is pending or has failed and is in use by any other resources within the account.",
"DisplayName": "AWS ACM Certificate Status",
"LogTypes": [
"AWS.ACM.Certificate"
],
"YAMLPath": "policies/aws_acm_policies/aws_acm_certificate_valid.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that all ACM certificates are using secure key and signature algorithms.",
"DisplayName": "AWS ACM Secure Algorithms",
"LogTypes": [
"AWS.ACM.Certificate"
],
"YAMLPath": "policies/aws_acm_policies/aws_acm_certificate_has_secure_algorithms.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that AMIs you have created are not configured to allow public access, which could result in accidental data loss. AMI's that you use but do not own are not evaluated by this policy.",
"DisplayName": "AWS AMI Sharing",
"LogTypes": [
"AWS.EC2.AMI"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ami_private.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that all application load balancers have an associated Web ACl to enforce protections against various web attacks.",
"DisplayName": "AWS Application Load Balancer Web ACL",
"LogTypes": [
"AWS.ELBV2.ApplicationLoadBalancer"
],
"YAMLPath": "policies/aws_elb_policies/aws_application_load_balancer_web_acl.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "Detects AWS Authentication events with IP Addresses not found in CrowdStrike's AIP List",
"DisplayName": "AWS Authentication from CrowdStrike Unmanaged Device",
"LogTypes": [
"AWS.CloudTrail",
"Crowdstrike.AIDMaster"
],
"YAMLPath": "queries/crowdstrike_queries/AWS_Authentication_from_CrowdStrike_Unmanaged_Device_Query.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "Detects AWS Authentication events with IP Addresses not found in CrowdStrike's AIP List",
"DisplayName": "AWS Authentication from CrowdStrike Unmanaged Device (crowdstrike_fdrevent table)",
"LogTypes": [
"AWS.CloudTrail",
"Crowdstrike.FDREvent"
],
"YAMLPath": "queries/aws_queries/AWS_Authentication_from_CrowdStrike_Unmanaged_Device_FDREvent.yml"
},
{
"AnalysisType": "Correlation Rule",
"Description": "Identifies when CreateRole and AttachAdminRolePolicy CloudTrail events occur in a short period of time. This sequence could indicate a potential security breach.",
"DisplayName": "AWS Backdoor Administrative IAM Role Created",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "correlation_rules/aws_create_backdoor_admin_iam_role.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Amazon Bedrock Guardrail was updated or deleted. Amazon Bedrock Guardrails are used to implement application-specific safeguards based on your use cases and responsible AI policies. Updating or deleting a guardrail can have security implications to your AI workloads.",
"DisplayName": "AWS Bedrock Guardrail Updated or Deleted",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_bedrock_guardrail_update_delete.yml"
},
{
"AnalysisType": "Rule",
"Description": "An Amazon Bedrock Model Invocation Logging Configuration was deleted. Use model invocation logging to collect metadata, requests, and responses for all model invocations in your account. Deleting a model invocation logging configuration can have security implications to your AI workloads.",
"DisplayName": "AWS Bedrock Model Invocation Logging Configuration Deleted",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_bedrock_deletemodelinvocationloggingconfiguration.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that all EC2 volumes that contain CDE are encrypted. Be sure to configure CDE definitions before enabling this policy.",
"DisplayName": "AWS CDE EC2 Volume Encryption",
"LogTypes": [
"AWS.EC2.Volume"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_cde_volume_encrypted.yml"
},
{
"AnalysisType": "Policy",
"Description": "A stack has drifted from its defined configuration.",
"DisplayName": "AWS CloudFormation Stack Drift",
"LogTypes": [
"AWS.CloudFormation.Stack"
],
"YAMLPath": "policies/aws_cloudformation_policies/aws_cloudformation_stack_drifted.yml"
},
{
"AnalysisType": "Policy",
"Description": "Associating IAM roles with CloudFormation stacks ensures least privilege when making changes to your account.",
"DisplayName": "AWS CloudFormation Stack IAM Service Role",
"LogTypes": [
"AWS.CloudFormation.Stack"
],
"YAMLPath": "policies/aws_cloudformation_policies/aws_cloudformation_stack_uses_iam_role.yml"
},
{
"AnalysisType": "Policy",
"Description": "Protects a CloudFormation stack from accidentally being deleted. If you attempt to delete a stack with termination protection enabled, the deletion fails and the stack, including its status, will remain unchanged.",
"DisplayName": "AWS CloudFormation Stack Termination Protection",
"LogTypes": [
"AWS.CloudFormation.Stack"
],
"YAMLPath": "policies/aws_cloudformation_policies/aws_cloudformation_termination_protection.yml"
},
{
"AnalysisType": "Rule",
"Description": "Adversaries may attempt to get a listing of accounts on a system or within an environment. This information can help adversaries determine which accounts exist to aid in follow-on behavior.",
"DisplayName": "AWS CloudTrail Account Discovery",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_account_discovery.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detects when an actor attempts to remove an AWS account from an Organization. Security configurations are often defined at the organizational level. Leaving the organization can disrupt or totally shut down these controls.",
"DisplayName": "AWS CloudTrail Attempt To Leave Org",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_attempt_to_leave_org.yml"
},
{
"AnalysisType": "Policy",
"Description": "CloudTrail supports sending data and management events to CloudWatch Logs. This setup can be used for real-time processing of all CloudTrail data events.",
"DisplayName": "AWS CloudTrail CloudWatch Logs",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_cloudwatch_logs.yml"
},
{
"AnalysisType": "Policy",
"Description": "Users with permissions to disable or reconfigure CloudTrail should be limited.",
"DisplayName": "AWS CloudTrail Least Privilege Access",
"LogTypes": [
"AWS.IAM.Group"
],
"YAMLPath": "policies/aws_iam_policies/aws_cloudtrail_least_privilege.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that CloudTrail Logs are encrypted at rest with customer managed KMS key.",
"DisplayName": "AWS CloudTrail Log Encryption",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_log_encryption.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that CloudTrail logs have file integrity validation enabled.",
"DisplayName": "AWS CloudTrail Log Validation",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_log_validation.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that at least one CloudTrail has management (control plane) operations logged.",
"DisplayName": "AWS CloudTrail Management Events Enabled",
"LogTypes": [
"AWS.CloudTrail.Meta"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "This detection looks for *AccountPasswordPolicy events in AWS CloudTrail logs. If these events occur in a short period of time from the same ARN, it could constitute Password Policy reconnaissance.",
"DisplayName": "AWS CloudTrail Password Policy Discovery",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_password_policy_discovery.yml"
},
{
"AnalysisType": "Rule",
"Description": "Threat actors who successfully compromise a victim's AWS account, whether through stolen credentials, exposed access keys, exploited IAM misconfigurations, vulnerabilities in third-party applications, or the absence of Multi-Factor Authentication (MFA), can exploit unused regions as safe zones for malicious activities. These regions are often overlooked in monitoring and security setups, making them an attractive target for attackers to operate undetected.",
"DisplayName": "AWS Cloudtrail Region Enabled",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_region_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detects when an S3 bucket containing CloudTrail logs has been modified to delete data after a short period of time.",
"DisplayName": "AWS CloudTrail Retention Lifecycle Too Short",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_short_lifecycle.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that the bucket receiving CloudTrail Logs is configured with S3 Access Logging. This audits all creation, modification, or deletion to CloudTrail audit logs.",
"DisplayName": "AWS CloudTrail S3 Bucket Access Logging",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_s3_bucket_access_logging.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that CloudTrail S3 buckets are not publicly accessible.",
"DisplayName": "AWS CloudTrail S3 Bucket Public",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "policies/aws_cloudtrail_policies/aws_cloudtrail_s3_bucket_public.yml"
},
{
"AnalysisType": "Rule",
"Description": "",
"DisplayName": "AWS CloudTrail SES Check Identity Verifications",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_ses_check_identity_verifications.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detect when someone checks how many emails can be delivered via SES",
"DisplayName": "AWS CloudTrail SES Check Send Quota",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_ses_check_send_quota.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detect when a user inquires whether SES Sending is enabled.",
"DisplayName": "AWS CloudTrail SES Check SES Sending Enabled",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_ses_check_ses_sending_enabled.yml"
},
{
"AnalysisType": "Correlation Rule",
"Description": "",
"DisplayName": "AWS CloudTrail SES Enumeration",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_ses_enumeration.yml"
},
{
"AnalysisType": "Rule",
"Description": "",
"DisplayName": "AWS CloudTrail SES List Identities",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_cloudtrail_ses_list_identities.yml"
},
{
"AnalysisType": "Policy",
"Description": "AWS automatically performs server-side encryption of logs, but you can encrypt with your own CMK to protect extra sensitive log data.",
"DisplayName": "AWS CloudWatch Log Encryption",
"LogTypes": [
"AWS.CloudWatch.LogGroup"
],
"YAMLPath": "policies/aws_cloudwatch_policies/aws_cloudwatch_loggroup_encrypted.yml"
},
{
"AnalysisType": "Policy",
"Description": "By default, logs are kept indefinitely and never expire. You can adjust the retention policy for each log group, keeping the indefinite retention, or choosing a specific retention period.",
"DisplayName": "AWS CloudWatch Logs Data Retention",
"LogTypes": [
"AWS.CloudWatch.LogGroup"
],
"YAMLPath": "policies/aws_cloudwatch_policies/aws_cloudwatch_loggroup_data_retention.yml"
},
{
"AnalysisType": "Rule",
"Description": "An AWS command was executed on a Linux instance",
"DisplayName": "AWS command executed on the command line",
"LogTypes": [
"Osquery.Differential"
],
"YAMLPath": "rules/osquery_rules/osquery_linux_aws_commands.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.",
"DisplayName": "AWS Compromised IAM Key Quarantine",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_iam_compromised_key_quarantine.yml"
},
{
"AnalysisType": "Policy",
"Description": "You can have AWS Config record supported types of global resources, such as IAM users, groups, roles, and customer managed policies.",
"DisplayName": "AWS Config Global Resources",
"LogTypes": [
"AWS.Config.Recorder.Meta"
],
"YAMLPath": "policies/aws_config_policies/aws_config_global_resources.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the config recorder is operational and capturing changes to your account without error.",
"DisplayName": "AWS Config Recording Status",
"LogTypes": [
"AWS.Config.Recorder"
],
"YAMLPath": "policies/aws_config_policies/aws_config_recording_no_error.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensurers that you have a comprehensive configuration audit in place for all resource types in AWS.",
"DisplayName": "AWS Config Records All Resource Types",
"LogTypes": [
"AWS.Config.Recorder"
],
"YAMLPath": "policies/aws_config_policies/aws_config_all_resource_types.yml"
},
{
"AnalysisType": "Rule",
"Description": "An AWS Config Recorder or Delivery Channel was created",
"DisplayName": "AWS Config Service Created",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_config_service_created.yml"
},
{
"AnalysisType": "Rule",
"Description": "An AWS Config Recorder or Delivery Channel was disabled or deleted",
"DisplayName": "AWS Config Service Disabled",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_config_service_disabled_deleted.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the config recorder is operational and capturing changes to your account.",
"DisplayName": "AWS Config Status",
"LogTypes": [
"AWS.Config.Recorder"
],
"YAMLPath": "policies/aws_config_policies/aws_config_recording_enabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "",
"DisplayName": "AWS Console Login",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_console_login.yml"
},
{
"AnalysisType": "Correlation Rule",
"Description": "A user has logged into the AWS console without authenticating via Okta. This rule requires AWS SSO via Okta and both log sources configured.",
"DisplayName": "AWS Console Sign-In NOT PRECEDED BY Okta Redirect",
"LogTypes": [
"AWS.CloudTrail",
"Okta.SystemLog"
],
"YAMLPath": "correlation_rules/aws_console_sign-in_without_okta.yml"
},
{
"AnalysisType": "Rule",
"Description": "Identify principles retrieving a high number of SSM Parameters of type 'SecretString'.",
"DisplayName": "AWS Decrypt SSM Parameters",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_ssm_decrypt_ssm_params.yml"
},
{
"AnalysisType": "Rule",
"Description": "Identifies clients that may be performing DNS lookups associated with common currency mining pools.",
"DisplayName": "AWS DNS Crypto Domain",
"LogTypes": [
"AWS.VPCDns",
"OCSF.DnsActivity"
],
"YAMLPath": "rules/aws_vpc_flow_rules/aws_dns_crypto_domain.yml"
},
{
"AnalysisType": "Rule",
"Description": "Detects when logs for a DNS Resolver have been removed.",
"DisplayName": "AWS DNS Logs Deleted",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_dns_logs_deleted.yml"
},
{
"AnalysisType": "Policy",
"Description": "DynamoDB Auto Scaling can dynamically adjust provisioned throughput capacity in response to traffic patterns. This enables a table to increase its provisioned read and write capacity to handle sudden increases in traffic",
"DisplayName": "AWS DynamoDB Table Autoscaling",
"LogTypes": [
"AWS.DynamoDB.Table"
],
"YAMLPath": "policies/aws_dynamodb_policies/aws_dynamodb_autoscaling.yml"
},
{
"AnalysisType": "Policy",
"Description": "DynamoDB Auto Scaling can dynamically adjust provisioned throughput capacity in response to traffic patterns. This enables a table to increase its provisioned read and write capacity to handle sudden increases in traffic",
"DisplayName": "AWS DynamoDB Table Autoscaling Configuration",
"LogTypes": [
"AWS.DynamoDB.Table"
],
"YAMLPath": "policies/aws_dynamodb_policies/aws_dynamodb_autoscaling_configuration.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy validates that all DynamoDB tables have a TTL field configured.",
"DisplayName": "AWS DynamoDB Table TTL",
"LogTypes": [
"AWS.DynamoDB.Table"
],
"YAMLPath": "policies/aws_dynamodb_policies/aws_dynamodb_table_ttl_enabled.yml"
},
{
"AnalysisType": "Policy",
"Description": "Checks that AWS EC2 AMI's are only launched on approved dedicated hosts.",
"DisplayName": "AWS EC2 AMI Approved Host",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_ami_approved_host.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the EC2 instance is running with an instance type approved for its AMI.",
"DisplayName": "AWS EC2 AMI Approved Instance Type",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_ami_approved_instance_type.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the EC2 instance was launched with a tenancy approved for its AMI.",
"DisplayName": "AWS EC2 AMI Approved Tenancy",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_ami_approved_tenancy.yml"
},
{
"AnalysisType": "Scheduled Query",
"Description": "Multiple different discovery commands were executed by the same EC2 instance.",
"DisplayName": "AWS EC2 Discovery Commands Executed",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "queries/aws_queries/ec2_discovery_commands_query.yml"
},
{
"AnalysisType": "Rule",
"Description": "An entity has accessed the user data scripts of multiple EC2 instances.",
"DisplayName": "AWS EC2 Download Instance User Data",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_ec2_download_instance_user_data.yml"
},
{
"AnalysisType": "Rule",
"Description": "Identifies disabling of default EBS encryption. Disabling default encryption does not change the encryption status of existing volumes.",
"DisplayName": "AWS EC2 EBS Encryption Disabled",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_ec2_ebs_encryption_disabled.yml"
},
{
"AnalysisType": "Rule",
"Description": "Checks CloudTrail for occurrences of EC2 Image Actions.",
"DisplayName": "AWS EC2 Image Monitoring",
"LogTypes": [
"AWS.CloudTrail"
],
"YAMLPath": "rules/aws_cloudtrail_rules/aws_ec2_monitoring.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures the given EC2 instance is running an AMI from the approved list of AMI's.",
"DisplayName": "AWS EC2 Instance Approved AMI",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_instance_approved_ami.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures the given EC2 Instance is running on an approved dedicated host.",
"DisplayName": "AWS EC2 Instance Approved Host",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_instance_approved_host.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the EC2 instance is running on one of the approved instance types.",
"DisplayName": "AWS EC2 Instance Approved Instance Type",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_instance_approved_instance_type.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures the given EC2 Instance is running with an approved tenancy option. The possible tenancy options are dedicated, host, and default.",
"DisplayName": "AWS EC2 Instance Approved Tenancy",
"LogTypes": [
"AWS.EC2.Instance"
],
"YAMLPath": "policies/aws_ec2_policies/aws_ec2_instance_approved_tenancy.yml"
},
{
"AnalysisType": "Policy",
"Description": "This policy ensures that the given EC2 Instance is running in an approved VPC.",