Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsAwsKmsKeyDeletion

Detects the scheduled deletion of KMS keys.

Source table → cloud.aws.cloudtrail

Expand
titleSecOpsAwsUnapprovedUserApiActivity

Detects AWS API activity by users who are not explicitly authorized from an allow list.

Detection of unapproved users interacting with the AWS API can prevent, abuse, fraud, and other malicious operations from being executed.

Source table → cloud.aws.cloudtrail

AWS CloudWatch alerts

Expand
titleAWS CloudWatch - AWS Detect STS Get Session Token Abuse

This alert detects actions to get STS session tokens, which can be used to move laterally or escalate privileges in AWS.

Source table → cloud.aws.cloudtrail 

...