...
AWS is one of the biggest cloud providers in the world and will enable your organization to build, run and manage applications across multiple environments. This alert pack is a bundle of Devo’s Security Operations out-of-the-box detections that can help you obtain a quick coverage of alerts.
Included alerts
| ||||
SecOpsAWSOpsWorksDescribePermissionsEvent | SecOpsAwsRoleCreated | SecOpsAwsSqsListQueues | ||
SecOpsAwsUpdateSAMLProvider | SecOpsAWSIAMUserGeneratingAccessDeniedErrorsAcrossMultipleActions | SecOpsAWSPermissionsBoundaryModifiedToRole | ||
SecOpsAWSSamlAccess | SecOpsAWSRootLogin | SecOpsLog4ShellVulnerabilityCloudAWS | ||
SecOpsAWSPermissionsBoundaryLiftedtoUser | SecOpsAWSSecretsManagerSensitiveAdminActionObserved | SecOpsAwsKmsSensitiveActivity | ||
SecOpsAWSMultipleFailedConsoleLoginsFromASourceIP | SecOpsAwsCloudTrailReconEvent | SecOpsAwsECRContainerScanningFindingsCritical | ||
SecOpsAWSIAMPolicyAppliedToGroup | SecOpsAWSPublicS3BucketExposed | SecOpsAWSOpenNetworkACLs | ||
SecOpsAWSLoggingConfigurationChangeObservedDeleteTrail | SecOpsAWSIAMPolicyAppliedToRole | SecOpsAWSLoggingConfigurationChangeObservedRemoveTags | ||
SecOpsAwsECRContainerUploadOutsideBusinessHours | SecOpsAWSUserSuccessfulLoginWithoutMFA | SecOpsAwsS3EncryptWithKMSKey | ||
SecOpsAWSDetectUsersCreatingKeysWithEncryptPolicyWithoutMFA | SecOpsAwsDbSnapshotCreated | SecOpsAWSExcessiveSecurityScanning | ||
SecOpsAwsEc2KeyAction | SecOpsAWSLoggingConfigurationChangeObservedStopLogging | SecOpsAwsMasterKeyDisabledOrDeletion | ||
SecOpsAWSIAMPolicyAppliedToUser | SecOpsAWSIAMDeletePolicy | SecOpsAWSCreatePolicyVersionToAllowAllResources | ||
SecOpsAWSCreateaccesskey | SecOpsAWSIAMCreateUserActionObserved | SecOpsAWSNewUserPoolClientCreated | ||
SecOpsAWSMultipleFailedConsoleLogins | SecOpsAWSNetworkAccessControlListDeleted | SecOpsAwsEcrImageUpload | ||
SecOpsAWSPermissionsBoundaryModifiedToUser | SecOpsAWSPermissionsBoundaryLiftedtoRole | SecOpsAWSIamSuccessfulGroupDeletion | ||
SecOpsAWSUpdateloginprofile | SecOpsAWSSetdefaultpolicyversion | SecOpsAwsPermanentKeyCreation | ||
SecOpsAWSDetectStsAssumeRoleAbuse | SecOpsAwsStsPossibleSessionTokenAbuse | SecOpsAwsGetSecretFromNonAmazonIp | ||
SecOpsAWSIAMAssumeRolePolicyBruteForce | SecOpsAwsKmsKeyDeletion | SecOpsAWSECRContainerScanningFindingsLowInformationalUnknown |
Prerequisites
To use this alert pack, you must have the following data sources available in your domain:
...