Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsAwsEc2KeyAction

Detects any actions observed that create, import, or delete access keys to EC2.

Source table → cloud.aws.cloudtrail

Expand
titleSecOpsAwsKmsKeyDeletion

Detects the scheduled deletion of KMS keys.

Source table → cloud.aws.cloudtrail

AWS CloudWatch alerts

Expand
titleAWS CloudWatch - AWS Detect STS Get Session Token Abuse

This alert detects actions to get STS session tokens, which can be used to move laterally or escalate privileges in AWS.

Source table → cloud.aws.cloudtrail 

...