AWS EC2 Route Table Modified or Deleted

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Identifies AWS CloudTrail events where an EC2 route table or association has been modified or deleted. Route table or association modifications can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is aNew Termsrule that detects the first instance of this behavior by theaws.cloudtrail.user_identity.arnfield in the last 10 days.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_AWS_EC2_ROUTE_TABLE_MODIFIED_OR_DELETED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS