Skip to content
This repository was archived by the owner on Sep 16, 2026. It is now read-only.

Latest commit

 

History

History
 
 

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 

README.md

Test Scenario - Data Enrichment with Tines

Usage

This CloudTrail log is an example used for enrichment and feedback into Panther.

# Export some variables
$ export BUCKET=my-bucket
$ export AWSACCOUNTID=123456789012
$ export AWS_REGION=us-east-1
# Send the sample data
$ python send_data.py --account-id $AWSACCOUNTID --region $AWS_REGION --compromise-datetime '2020-11-30T18:34:12+00:00' --bucket-name $BUCKET  --file enrichment-example/attacker_cloudtrail.yml

Background Info

These CloudTrail logs show failed logins, followed by a successful one, followed by some actions. The user IP is from a known malware list, which triggers findings in Threat Intel lookups.

Usernames

N/A

Data

  • AWS.CloudTrail