LoFP LoFP / dev, uat, sat environment. you should apply this rule with prod environment only.

Techniques

Sample rules

AWS SecurityHub Findings Evasion

Description

Detects the modification of the findings on SecurityHub.

Detection logic

condition: selection
selection:
  eventName:
  - BatchUpdateFindings
  - DeleteInsight
  - UpdateFindings
  - UpdateInsight
  eventSource: securityhub.amazonaws.com