Isai
fe327a7560
[Rule Tunings] AWS Role Assumption By Service / User ( #4827 )
...
AWS Role Assumption By Service
The newest versions of this rule seem fine in telemetry and the rule executes as expected
- removed MD from description
- adjusted execution window for 1 m look back
- fixed inaccuracies in Investigation Guide
- added Lateral Movement tag
- adjusted highlighted fields
- reduced history window from 14 to 10 days
AWS Role Assumption By User
This rule seem fine in telemetry and the rule executes as expected
- removed MD from description
- fixed inaccuracies in Investigation Guide
- added Lateral Movement tag
- adjusted highlighted fields
- added `cloud.account.id` to new_terms field to account for duplicate user.names across cloud accounts
- replaced new terms flattened field for `aws.cloudtrail.resources.arn`, which gives the same result and remains consistent with the other rule.
2025-06-24 18:07:18 -04:00
..
2025-01-22 11:17:38 -06:00
2025-01-22 14:43:30 -06:00
2025-06-06 15:08:48 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2024-05-23 00:45:10 +05:30
2025-02-03 21:27:50 +05:30
2025-02-03 21:27:50 +05:30
2025-01-31 10:35:18 -05:00
2025-01-22 11:17:38 -06:00
2024-11-08 23:11:18 -05:00
2025-06-17 13:58:26 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-06 14:11:54 -04:00
2025-06-06 14:11:54 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 13:19:22 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-06-17 14:51:18 -04:00
2025-02-03 21:27:50 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-24 17:22:20 -04:00
2025-03-21 10:05:24 -04:00
2025-03-21 10:05:24 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:53:36 -05:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2024-11-05 02:09:05 -05:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-15 14:11:58 -05:00
2025-03-20 20:32:07 +05:30
2025-02-03 21:27:50 +05:30
2025-04-30 16:25:03 -04:00
2025-01-15 14:11:58 -05:00
2024-05-23 00:45:10 +05:30
2025-06-02 11:32:05 -04:00
2025-04-21 12:06:57 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-15 13:55:45 -05:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2021-07-21 15:24:56 -06:00
2025-04-21 11:02:14 -04:00
2025-06-06 14:11:54 -04:00
2025-02-03 23:03:20 +05:30
2025-01-22 11:17:38 -06:00
2025-04-24 15:39:51 -04:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 15:03:55 -04:00
2025-06-24 18:07:18 -04:00
2025-06-24 18:07:18 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:05:40 -05:00