LoadBalancer Security Group Modification

Last updated on:

Applies to: Log360Log360 Cloud

About the rule

Rule Type

Standard

Rule Description

Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "LoadBalancer Security Group Modification" select Action1.CALLER,Action1.PRINCIPALID,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS

Author

jamesc-grafana