AWS Lambda Function Created or Updated
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Identifies when an AWS Lambda function is created or updated. AWS Lambda lets you run code without provisioning or managing servers. Adversaries can create or update Lambda functions to execute malicious code, exfiltrate data, or escalate privileges. This is a building block rule that does not generate alerts, but signals when a Lambda function is created or updated that matches the rule's conditions. To generate alerts, create a rule that uses this signal as a building block.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_AWS_LAMBDA_FUNCTION_CREATED_OR_UPDATED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS
Detection
Execution Mode
realtime
Log Sources
AWS


