Isai
1ed322f8d9
[Rule Tuning] AWS SSM SendCommand Execution by Rare User ( #4828 )
...
Rule is triggering as expected, very low instances of alerts in telemetry
- adjusted execution window
- slight edits to IG for accuracy
- removed exclusion `and not aws.cloudtrail.user_identity.arn: *AWSServiceRoleForAmazonSSM/StateManagerService*` from the query. This is a service-linked role meant to be used by AWS internal services. Therefore, the existing exclusion `and not source.address: "ssm.amazonaws.com"` already excludes the use of this role by the SSM service. I show this in the screenshot below. This will remove the use of wildcards in the query and improve performance.
- changed the new terms fields to use combination of `cloud.account.id` and `user.name` so that only roles (and not individual role sessions) are being evaluated. adding `cloud.account.id` accounts for duplicate user.names across multiple accounts.
2025-06-24 17:22:20 -04:00
..
2025-01-22 11:17:38 -06:00
2025-01-22 14:43:30 -06:00
2025-06-06 15:08:48 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2024-05-23 00:45:10 +05:30
2025-02-03 21:27:50 +05:30
2025-02-03 21:27:50 +05:30
2025-01-31 10:35:18 -05:00
2025-01-22 11:17:38 -06:00
2024-11-08 23:11:18 -05:00
2025-06-17 13:58:26 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-06 14:11:54 -04:00
2025-06-06 14:11:54 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 13:19:22 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-06-17 14:51:18 -04:00
2025-02-03 21:27:50 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-24 17:22:20 -04:00
2025-03-21 10:05:24 -04:00
2025-03-21 10:05:24 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:53:36 -05:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2024-11-05 02:09:05 -05:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-15 14:11:58 -05:00
2025-03-20 20:32:07 +05:30
2025-02-03 21:27:50 +05:30
2025-04-30 16:25:03 -04:00
2025-01-15 14:11:58 -05:00
2024-05-23 00:45:10 +05:30
2025-06-02 11:32:05 -04:00
2025-04-21 12:06:57 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-15 13:55:45 -05:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2021-07-21 15:24:56 -06:00
2025-04-21 11:02:14 -04:00
2025-06-06 14:11:54 -04:00
2025-02-03 23:03:20 +05:30
2025-01-22 11:17:38 -06:00
2025-04-24 15:39:51 -04:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 15:03:55 -04:00
2025-01-31 10:35:18 -05:00
2025-01-22 11:17:38 -06:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:05:40 -05:00