Files
blue-team-tools/rules/cloud/aws/cloudtrail/aws_new_lambda_layer_attached.yml
T

29 lines
1.2 KiB
YAML
Raw Normal View History

title: AWS New Lambda Layer Attached
id: 97fbabf8-8e1b-47a2-b7d5-a418d2b95e3d
2022-10-09 16:54:04 +02:00
status: test
2022-10-25 07:34:10 +02:00
description: |
Detects when a user attached a Lambda layer to an existing Lambda function.
A malicious Lambda layer could execute arbitrary code in the context of the function's IAM role.
This would give an adversary access to resources that the function has access to.
references:
- https://docs.aws.amazon.com/lambda/latest/dg/API_UpdateFunctionConfiguration.html
- https://github.com/clearvector/lambda-spy
2022-10-09 16:54:04 +02:00
author: Austin Songer
date: 2021-09-23
modified: 2025-03-17
2022-10-09 16:54:04 +02:00
tags:
- attack.privilege-escalation
logsource:
2021-11-14 09:56:59 +01:00
product: aws
service: cloudtrail
detection:
selection:
eventSource: lambda.amazonaws.com
2022-09-01 15:22:26 +02:00
eventName|startswith: 'UpdateFunctionConfiguration'
requestParameters.layers|contains: '*'
2021-10-05 17:52:52 +01:00
condition: selection
falsepositives:
2022-10-09 16:54:04 +02:00
- Lambda Layer being attached may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Lambda Layer being attached from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low