...
Expand | ||
---|---|---|
| ||
Detects actions taken by users to encrypt S3 buckets using KMS keys. Source table → |
Expand | ||
---|---|---|
| ||
This alert triggers when a user logs into the console for the first time in a year. Source table → |
Expand | ||
---|---|---|
| ||
An AWS console successfully without MFA login was detected. AWS security best practices are recommended to enable this security measure for console access login. Source table → |
AWS CloudWatch alerts
Expand | ||
---|---|---|
| ||
This alert detects actions to get STS session tokens, which can be used to move laterally or escalate privileges in AWS. Source table → |
...
Expand | ||
---|---|---|
| ||
Detects possible large files being moved via AWS VPC logs. Source table → |
Expand | ||
---|---|---|
| ||
Actions observed as blocked for sending large amounts of data from AWS out to the internet. Source table → |