Commit Graph

3 Commits

Author SHA1 Message Date
Rachel Rice 78d3fa4795 Update AWS STS AssumeRole Misuse rule
Update selection criteria for AWS STS AssumeRole Misuse rule for any event by an AssumedRole userIdentity.
Closes SigmaHQ/sigma#1963.
2021-09-02 17:40:35 +01:00
frack113 b9a355e3f4 cleanup falsepositives 2021-08-20 17:18:32 +02:00
Rachel Rice f09b3ea4b1 Update AWS CloudTrail rules
aws_ec2_disable_encryption.yml
Remove `status: success` from selection criteria, not required

aws_ec2_vm_export_failure.yml
Remove filter3:
```
eventName: 'ConsoleLogin'
responseElements|contains: 'Failure'
```
Incompatible with selection criteria `eventName: 'CreateInstanceExportTask'`

aws_ec2_download_userdata.yml, aws_iam_backdoor_users_keys.yml, aws_rds_change_master_password.yml, aws_rds_public_db_restore.yml
Update reference

aws_sts_assumedrole_misuse.yml
Rename to aws_sts_assumerole_misuse.yml
Update references to "AssumedRole" to "AssumeRole"
Update selection criteria of `userIdentity.sessionContext: Role` to `userIdentity.sessionContext.sessionIssuer.type: Role`
2021-08-20 13:43:00 +01:00