Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsAwsUnapprovedUserApiActivity

Detects AWS API activity by users who are not explicitly authorized from an allow list.

Detection of unapproved users interacting with the AWS API can prevent, abuse, fraud, and other malicious operations from being executed.

Source table → cloud.aws.cloudtrail

Expand
titleSecOpsAwsUpdateSAMLProvider

Detects actions that update SAML the provider configuration

Source table → cloud.aws.cloudtrail

AWS CloudWatch alerts

Expand
titleAWS CloudWatch - AWS Detect STS Get Session Token Abuse

This alert detects actions to get STS session tokens, which can be used to move laterally or escalate privileges in AWS.

Source table → cloud.aws.cloudtrail 

...