Isai
590cc9cbbd
[Tuning] First Occurrence of STS GetFederationToken Request by User ( #5007 )
...
Rule is executing as expected, however it is alerting on failed requests. Low alert telemetry.
This tuning:
- removed markdown and edited description to be more specific
- reduced execution window for 1 min lookback
- name change to add `AWS` consistent with all other rules
- added references that reflect in the wild threats and persistence usage
- increased risk_score and severity to medium accounting for usage as persistence mechanism in the wild
- added Persistence tag and Mitre tactic, technique, subtechnique
- added `event.outcome: success` criteria to query
- edited investigation guide to be more accurate reflection of steps required for investigating alert, including appropriate response action
- added highlighted fields
** Note: only IAMUser and Root user identities can call this actions so we can use `aws.cloudtrail.user_identity.arn` as the new terms field without worrying about Role vs Role + Session issue seen with other new_terms rules
2025-08-29 13:08:59 -04:00
..
2025-01-22 11:17:38 -06:00
2025-01-22 14:43:30 -06:00
2025-06-06 15:08:48 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2024-05-23 00:45:10 +05:30
2025-08-25 12:00:47 -04:00
2025-02-03 21:27:50 +05:30
2025-07-18 19:15:36 -04:00
2025-01-22 11:17:38 -06:00
2024-11-08 23:11:18 -05:00
2025-06-17 13:58:26 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-06 14:11:54 -04:00
2025-06-06 14:11:54 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-08-29 13:08:59 -04:00
2025-07-18 19:15:36 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-07-18 19:15:36 -04:00
2025-08-05 19:35:41 -04:00
2025-08-05 19:35:41 -04:00
2025-07-18 19:15:36 -04:00
2025-08-25 11:44:58 -04:00
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2025-08-29 12:36:21 -04:00
2025-06-27 13:24:27 -04:00
2025-07-18 19:15:36 -04:00
2025-03-21 10:05:24 -04:00
2025-07-18 19:15:36 -04:00
2025-07-21 10:12:13 +05:30
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:53:36 -05:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2024-11-05 02:09:05 -05:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-07-18 19:15:36 -04:00
2025-08-05 19:35:41 -04:00
2025-02-03 21:27:50 +05:30
2025-08-05 19:35:41 -04:00
2025-07-18 19:15:36 -04:00
2024-05-23 00:45:10 +05:30
2025-08-05 19:35:41 -04:00
2025-04-21 12:06:57 -04:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-15 13:55:45 -05:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2021-07-21 15:24:56 -06:00
2025-04-21 11:02:14 -04:00
2025-06-06 14:11:54 -04:00
2025-02-03 23:03:20 +05:30
2025-07-18 19:15:36 -04:00
2025-07-15 19:13:16 -04:00
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-08-22 14:48:39 -04:00
2025-08-05 19:35:41 -04:00
2025-08-05 19:35:41 -04:00
2025-08-05 19:35:41 -04:00
2025-07-18 19:15:36 -04:00
2025-01-22 11:17:38 -06:00
2025-07-18 19:15:36 -04:00
2025-06-24 18:07:18 -04:00
2025-06-24 18:07:18 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-02-20 10:05:40 -05:00