elastic / detection-rules

Home Page:https://www.elastic.co/guide/en/security/current/detection-engine-overview.html

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[Rule Tuning] AWS Route Table Created

leandrojmp opened this issue · comments

Link to rule

AWS Route Table Created

Description

This rules looks for the actions CreateRoute and CreateRouteTable with the event.provider as cloudtrail.amazonaws.com, but those actions are EC2 actions, so the provider will be ec2.amazonaws.com.

WIth its currents filter it seems that this rule will never trigger.

Example Data

Current filter with event.provider as cloudtrail.amazonaws.com
Screenshot from 2024-03-08 15-21-18

Using event.provider as ec2.amazonaws.com
Screenshot from 2024-03-08 15-21-05