You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Simplify dedup() to source IP only. With read-only events filtered
at rule(), the previous IP:account:readOnly key was effectively
IP:account, which still fans out one alert per touched account.
Bulk root operations from a single IP (e.g., org-wide credential
cleanup, but also a single-IP attacker touching N accounts) now
collapse to one alert. Tradeoff: analysts must inspect the alert's
event list to see full account scope.
Medium Risk
Changes when root misuse alerts fire and how they group across accounts; missed read-only-only abuse is possible, but mutating root actions remain covered at High severity.
Overview Root Account Activity now fires only on non-read-only successful root API calls (enumeration/console reads are excluded), with updated rule copy in indexes and detection-coverage.json.
Dedup keys alerts by source IP only instead of IP + account + readOnly, so many accounts touched from one IP produce a single alert (analysts rely on the alert event list for scope). The per-event LOW/HIGH severity() hook is removed because read-only events no longer match; YAML High applies to all hits.
A unit test asserts read-only root activity (e.g. ListAccessKeys with readOnly: true) does not trigger the rule.
Reviewed by Cursor Bugbot for commit 746bf9b. Bugbot is set up for automated code reviews on this repo. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
THREAT-732
Changes
at rule(), the previous IP:account:readOnly key was effectively
IP:account, which still fans out one alert per touched account.
Bulk root operations from a single IP (e.g., org-wide credential
cleanup, but also a single-IP attacker touching N accounts) now
collapse to one alert. Tradeoff: analysts must inspect the alert's
event list to see full account scope.
Testing