Sample rules
AWS ElastiCache Security Group Modified or Deleted
- source: elastic
- technicques:
- T1562
Description
Identifies when an ElastiCache security group has been modified or deleted.
Detection logic
event.dataset:aws.cloudtrail and event.provider:elasticache.amazonaws.com and event.action:("Delete Cache Security Group" or
"Authorize Cache Security Group Ingress" or "Revoke Cache Security Group Ingress" or "AuthorizeCacheSecurityGroupEgress" or
"RevokeCacheSecurityGroupEgress") and event.outcome:success
AWS ElastiCache Security Group Modified or Deleted
- source: sigma
- technicques:
- t1531
Description
Identifies when an ElastiCache security group has been modified or deleted.
Detection logic
condition: selection
selection:
eventName:
- DeleteCacheSecurityGroup
- AuthorizeCacheSecurityGroupIngress
- RevokeCacheSecurityGroupIngress
- AuthorizeCacheSecurityGroupEgress
- RevokeCacheSecurityGroupEgress
eventSource: elasticache.amazonaws.com