AWS EC2 Security Group Configuration Changed

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Identifies a change to an AWS Security Group Configuration. A security group is like a virtual firewall, and modifying configurations may allow unauthorized access. Threat actors may abuse this to establish persistence, exfiltrate data, or pivot in an AWS environment.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_AWS_EC2_SECURITY_GROUP_CONFIG_CHANGED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS