AWS EC2 Deprecated AMI Discovery
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Identifies when a user has queried for deprecated Amazon Machine Images (AMIs) in AWS. This may indicate an adversary whom is looking for outdated AMIs that may be vulnerable to exploitation. While deprecated AMIs are not inherently malicious or indicate breach, they may be more susceptible to vulnerabilities and should be investigated for potential security risks.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_AWS_EC2_AMI_DISCOVERED" AND (REQUESTPARAMETERS contains "includedeprecated:true") select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS
Detection
Execution Mode
realtime
Log Sources
AWS


