LoFP LoFP / t1686

t1686

TitleTags
admin activity
administrator scripts or activity.
firewall being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
firewall modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
firewall policy being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
firewall policy modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
legitimate admin activity
legitimate administration activities
legitimate administration activity
legitimate ports redirect
legitimate use of acls to enable customer and staff access from the public internet into a public vpc
network administrators
new subnets added requiring routing setup
new vpc creation requiring setup of a new route table
rule collections (application, nat, and network) being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
rule collections (application, nat, and network) modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
software installations
software installations and removal
unknown