Platform / product
aws Sigma detection rules
58 community-maintained Sigma detection rules in the library target the aws platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
AWS Config Disabling Channel/Recorder
highDetects AWS Config Service disabling
aws · cloudtrail
AWS EC2 Startup Shell Script Change
highDetects changes to the EC2 instance startup script. The shell script will be executed as root/SYSTEM every time the specific instances are booted up.
aws · cloudtrail
AWS GuardDuty Detector Deleted Or Updated
highDetects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities. Upon deletion, GuardDuty stops monitoring the environment and all existing findings are lost. Verify with the user identity that this activity is legitimate.
aws · cloudtrail
AWS GuardDuty Important Change
highDetects updates of the GuardDuty list of trusted IPs, perhaps to disable security alerts against malicious IPs.
aws · cloudtrail
AWS IAM S3Browser LoginProfile Creation
highDetects S3 Browser utility performing reconnaissance looking for existing IAM Users without a LoginProfile defined then (when found) creating a LoginProfile.
aws · cloudtrail
AWS IAM S3Browser Templated S3 Bucket Policy Creation
highDetects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
aws · cloudtrail
AWS IAM S3Browser User or AccessKey Creation
highDetects S3 Browser utility creating IAM User or AccessKey.
aws · cloudtrail
AWS Identity Center Identity Provider Change
highDetects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.
aws · cloudtrail
AWS KMS Imported Key Material Usage
highDetects the import or deletion of key material in AWS KMS, which can be used as part of ransomware attacks. This activity is uncommon and provides a high certainty signal.
aws · cloudtrail
AWS SecurityHub Findings Evasion
highDetects the modification of the findings on SecurityHub.
aws · cloudtrail
AWS User Login Profile Was Modified
highDetects activity when someone is changing passwords on behalf of other users. An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
aws · cloudtrail
AWS VPC Flow Logs Deleted
highDetects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into malicious operations.
aws · cloudtrail
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
highDetects when an instance identity has taken an action that isn't inside SSM. This can indicate that a compromised EC2 instance is being used as a pivot point.
aws · cloudtrail
Modification or Deletion of an AWS RDS Cluster
highDetects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
aws · cloudtrail
Potential Malicious Usage of CloudTrail System Manager
highDetect when System Manager successfully executes commands against an instance.
aws · cloudtrail
Restore Public AWS RDS Instance
highDetects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
aws · cloudtrail
AWS Bedrock Guardrail Deleted
mediumDetects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and allow unsafe or unauthorized model responses.
aws · cloudtrail
AWS Bedrock Guardrail Updated
mediumDetects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses.
aws · cloudtrail
AWS Bucket Deleted
mediumDetects the deletion of S3 buckets in AWS CloudTrail logs. Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.
aws · cloudtrail
AWS CloudTrail Important Change
mediumDetects disabling, deleting and updating of a Trail
aws · cloudtrail
AWS Console GetSigninToken Potential Abuse
mediumDetects potentially suspicious events involving "GetSigninToken". An adversary using the "aws_consoler" tool can leverage this console API to create temporary federated credential that help obfuscate which AWS credential is compromised (the original access key) and enables the adversary to pivot from the AWS CLI to console sessions without the need for MFA using the new access key issued in this request.
aws · cloudtrail
AWS Console Login Monitoring
mediumDetects AWS console logins from countries and IP addresses that are not recognized as legitimate for the organization. This alert can help identify potential unauthorized access attempts from unusual locations, which may indicate compromised credentials or malicious activity.
aws · cloudtrail
AWS ConsoleLogin Failed Authentication
mediumDetects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
aws · cloudtrail
AWS EC2 Disable EBS Encryption
mediumIdentifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
aws · cloudtrail
AWS ECS Task Definition That Queries The Credential Endpoint
mediumDetects when an Elastic Container Service (ECS) Task Definition includes a command to query the credential endpoint. This can indicate a potential adversary adding a backdoor to establish persistence or escalate privileges.
aws · cloudtrail
AWS EFS Fileshare Modified or Deleted
mediumDetects when a EFS Fileshare is modified or deleted. You can't delete a file system that is in use. If the file system has any mount targets, the adversary must first delete them, so deletion of a mount will occur before deletion of a fileshare.
aws · cloudtrail
AWS EFS Fileshare Mount Modified or Deleted
mediumDetects when a EFS Fileshare Mount is modified or deleted. An adversary breaking any file system using the mount target that is being deleted, which might disrupt instances or applications using those mounts.
aws · cloudtrail
AWS EnableRegion Command Monitoring
mediumDetects the use of the EnableRegion command in AWS CloudTrail logs. While AWS has 30+ regions, some of them are enabled by default, others must be explicitly enabled in each account separately. There may be situations where security monitoring does not cover some new AWS regions. Monitoring the EnableRegion command is important for identifying potential persistence mechanisms employed by adversaries, as enabling additional regions can facilitate continued access and operations within an AWS environment.
aws · cloudtrail
AWS IAM Backdoor Users Keys
mediumDetects AWS API key creation for a user by another user. Backdoored users can be used to obtain persistence in the AWS environment. Also with this alert, you can detect a flow of AWS keys in your org.
aws · cloudtrail
AWS Key Pair Import Activity
mediumDetects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
aws · cloudtrail
AWS RDS Master Password Change
mediumDetects the change of database master password. It may be a part of data exfiltration.
aws · cloudtrail
AWS Root Credentials
mediumDetects AWS root account usage
aws · cloudtrail
AWS S3 Bucket Versioning Disable
mediumDetects when S3 bucket versioning is disabled. Threat actors use this technique during AWS ransomware incidents prior to deleting S3 objects.
aws · cloudtrail
AWS SAML Provider Deletion Activity
mediumDetects the deletion of an AWS SAML provider, potentially indicating malicious intent to disrupt administrative or security team access. An attacker can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.
aws · cloudtrail
AWS Snapshot Backup Exfiltration
mediumDetects the modification of an EC2 snapshot's permissions to enable access from another account
aws · cloudtrail
AWS STS GetCallerIdentity Enumeration Via TruffleHog
mediumDetects the use of TruffleHog for AWS credential validation by identifying GetCallerIdentity API calls where the userAgent indicates TruffleHog. Threat actors leverage TruffleHog to enumerate and validate exposed AWS keys. Successful exploitation allows threat actors to confirm the validity of compromised AWS credentials, facilitating further unauthorized access and actions within the AWS environment.
aws · cloudtrail
AWS Successful Console Login Without MFA
mediumDetects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
aws · cloudtrail
AWS Suspicious SAML Activity
mediumIdentifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
aws · cloudtrail
Ingress/Egress Security Group Modification
mediumDetects when an account makes changes to the ingress or egress rules of a security group. This can indicate that an attacker is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to allow machines in that VPC/Subnet to contact a C&C server.
aws · cloudtrail
LoadBalancer Security Group Modification
mediumDetects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
aws · cloudtrail
New AWS Lambda Function URL Configuration Created
mediumDetects when a user creates a Lambda function URL configuration, which could be used to expose the function to the internet and potentially allow unauthorized access to the function's IAM role for AWS API calls. This could give an adversary access to the privileges associated with the Lambda service role that is attached to that function.
aws · cloudtrail
New Network Route Added
mediumDetects the addition of a new network route to a route table in AWS.
aws · cloudtrail
PUA - AWS TruffleHog Execution
mediumDetects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment. It has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the usage is authorized by security teams or potentially malicious.
aws · cloudtrail
RDS Database Security Group Modification
mediumDetects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
aws · cloudtrail
SES Identity Has Been Deleted
mediumDetects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities
aws · cloudtrail
AWS EC2 VM Export Failure
lowAn attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
aws · cloudtrail
AWS EKS Cluster Created or Deleted
lowIdentifies when an EKS cluster is created or deleted.
aws · cloudtrail
AWS ElastiCache Security Group Created
lowDetects when an ElastiCache security group has been created.
aws · cloudtrail
AWS ElastiCache Security Group Modified or Deleted
lowIdentifies when an ElastiCache security group has been modified or deleted.
aws · cloudtrail
AWS Glue Development Endpoint Activity
lowDetects possible suspicious glue development endpoint activity.
aws · cloudtrail
AWS New Lambda Layer Attached
lowDetects when a user attached a Lambda layer to an existing Lambda function. A malicious Lambda layer could execute arbitrary code in the context of the function's IAM role. This would give an adversary access to resources that the function has access to.
aws · cloudtrail
AWS Route 53 Domain Transfer Lock Disabled
lowDetects when a transfer lock was removed from a Route 53 domain. It is recommended to refrain from performing this action unless intending to transfer the domain to a different registrar.
aws · cloudtrail
AWS Route 53 Domain Transferred to Another Account
lowDetects when a request has been made to transfer a Route 53 domain to another AWS account.
aws · cloudtrail
AWS S3 Data Management Tampering
lowDetects when a user tampers with S3 data management in Amazon Web Services.
aws · cloudtrail
AWS STS AssumeRole Misuse
lowIdentifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
aws · cloudtrail
AWS STS GetSessionToken Misuse
lowIdentifies the suspicious use of GetSessionToken. Tokens could be created and used by attackers to move laterally and escalate privileges.
aws · cloudtrail
New Network ACL Entry Added
lowDetects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.
aws · cloudtrail
Potential Bucket Enumeration on AWS
lowLooks for potential enumeration of AWS buckets via ListBuckets.
aws · cloudtrail