LoFP LoFP / a private hosted zone may be asssociated with a vpc by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

AWS Route53 private hosted zone associated with a VPC

Description

Identifies when a Route53 private hosted zone has been associated with VPC.

Detection logic

event.dataset:aws.cloudtrail and event.provider:route53.amazonaws.com and event.action:AssociateVPCWithHostedZone and
event.outcome:success