Files
blue-team-tools/rules/cloud/aws/aws_macic_evasion.yml
T

37 lines
1012 B
YAML
Raw Normal View History

2021-07-26 15:26:17 +07:00
title: AWS Macie Evasion
2021-07-26 15:14:44 +07:00
id: 91f6a16c-ef71-437a-99ac-0b070e3ad221
status: experimental
description: Detects evade to Macie detection.
author: Sittikorn S
date: 2021/07/06
2021-07-26 15:38:34 +07:00
references:
2021-07-26 15:14:44 +07:00
- https://docs.aws.amazon.com/cli/latest/reference/macie/
tags:
2021-07-26 17:21:47 +07:00
- attack.defense_evasion
2021-07-26 15:14:44 +07:00
- attack.t1562.001
logsource:
2021-11-14 09:56:59 +01:00
product: aws
2021-07-26 15:14:44 +07:00
service: cloudtrail
detection:
selection:
eventName:
- 'ArchiveFindings'
- 'CreateFindingsFilter'
- 'DeleteMember'
- 'DisassociateFromMasterAccount'
- 'DisassociateMember'
- 'DisableMacie'
2021-07-26 21:27:59 +07:00
- 'DisableOrganizationAdminAccount'
2021-07-26 15:14:44 +07:00
- 'UpdateFindingsFilter'
- 'UpdateMacieSession'
- 'UpdateMemberSession'
- 'UpdateClassificationJob'
timeframe: 10m
2021-07-26 15:26:17 +07:00
condition: selection | count() by sourceIPAddress > 5
2021-07-26 15:14:44 +07:00
fields:
- sourceIPAddress
- userIdentity.arn
falsepositives:
- System or Network administrator behaviors
level: medium