Update conditions

This commit is contained in:
faloker
2020-02-12 22:20:15 +02:00
parent aacab37f84
commit ddf5f8ec23
2 changed files with 5 additions and 6 deletions
+1 -1
View File
@@ -16,7 +16,7 @@ detection:
selection_eventname:
- eventName: DescribeInstanceAttribute
timeframe: 30m
condition: selection_source AND selection_eventname AND selection_requesttype | count() > 10
condition: all of them | count() > 10
level: medium
falsepositives:
- Assets management software like device42
+4 -5
View File
@@ -11,11 +11,10 @@ logsource:
detection:
selection_source:
- eventSource: guardduty.amazonaws.com
events:
- eventName:
- CreateIPSet
condition: selection_source AND events
level: medium
selection_eventName:
- eventName: CreateIPSet
condition: all of them
level: high
falsepositives:
- Valid change in the GuardDuty (e.g. to ignore internal scanners)
tags: