Skip to content

AWS Root Activity Rule Dedup Tuning - #2097

Merged
zaynahsmith-dasilva merged 3 commits into
developfrom
aws_root_tuning
Jun 12, 2026
Merged

zaynahsmith-dasilva merged 3 commits into
developfrom
aws_root_tuning

Conversation

@zaynahsmith-dasilva

@zaynahsmith-dasilva zaynahsmith-dasilva commented Jun 12, 2026 •

Copy link
Copy Markdown
Contributor

Background

THREAT-732

Changes

  • Simplify dedup() to source IP only. With read-only events filtered
    at rule(), the previous IP:account:readOnly key was effectively
    IP:account, which still fans out one alert per touched account.
    Bulk root operations from a single IP (e.g., org-wide credential
    cleanup, but also a single-IP attacker touching N accounts) now
    collapse to one alert. Tradeoff: analysts must inspect the alert's
    event list to see full account scope.

Testing

@zaynahsmith-dasilva
zaynahsmith-dasilva requested review from a team as code owners June 12, 2026 16:54
@zaynahsmith-dasilva zaynahsmith-dasilva added the tuning detection tuning label Jun 12, 2026
@cursor

cursor Bot commented Jun 12, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes when root misuse alerts fire and how they group across accounts; missed read-only-only abuse is possible, but mutating root actions remain covered at High severity.

Overview
Root Account Activity now fires only on non-read-only successful root API calls (enumeration/console reads are excluded), with updated rule copy in indexes and detection-coverage.json.

Dedup keys alerts by source IP only instead of IP + account + readOnly, so many accounts touched from one IP produce a single alert (analysts rely on the alert event list for scope). The per-event LOW/HIGH severity() hook is removed because read-only events no longer match; YAML High applies to all hits.

A unit test asserts read-only root activity (e.g. ListAccessKeys with readOnly: true) does not trigger the rule.

Reviewed by Cursor Bugbot for commit 746bf9b. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread rules/aws_cloudtrail_rules/aws_root_activity.py Outdated
@zaynahsmith-dasilva
zaynahsmith-dasilva added this pull request to the merge queue Jun 12, 2026
Merged via the queue into develop with commit 389ffe6 Jun 12, 2026
18 checks passed
@zaynahsmith-dasilva
zaynahsmith-dasilva deleted the aws_root_tuning branch June 12, 2026 17:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tuning detection tuning

3 participants