added aws_root_account_usage.yml
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
title: Root credentials are used
|
||||
id: 8ad1600d-e9dc-4251-b0ee-a65268f29add
|
||||
status: experimental
|
||||
author: vitaliy0x1
|
||||
description: Detects Root account usage
|
||||
references:
|
||||
- https://docs.aws.amazon.com/IAM/latest/UserGuide/id_root-user.html
|
||||
logsource:
|
||||
service: CloudTrail
|
||||
detection:
|
||||
selection_usertype:
|
||||
- userIdentity.type: Root
|
||||
selection_eventtype:
|
||||
- eventType: AwsServiceEvent
|
||||
condition: selection_usertype AND NOT selection_eventtype
|
||||
level: medium
|
||||
falsepositives:
|
||||
- AWS Tasks That Require AWS Account Root User Credentials https://docs.aws.amazon.com/general/latest/gr/aws_tasks-that-require-root.html
|
||||
tags:
|
||||
- attack.t1078
|
||||
Reference in New Issue
Block a user