AWS EC2 Route Table Modified or Deleted
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Identifies AWS CloudTrail events where an EC2 route table or association has been modified or deleted. Route table or association modifications can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is aNew Termsrule that detects the first instance of this behavior by theaws.cloudtrail.user_identity.arnfield in the last 10 days.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_AWS_EC2_ROUTE_TABLE_MODIFIED_OR_DELETED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS
Detection
Execution Mode
realtime
Log Sources
AWS


