LoFP LoFP / legitimate users may subscribe to sns topics for legitimate purposes. ensure that the subscription is authorized before taking action.

Techniques

Sample rules

AWS SNS Rare Protocol Subscription by User

Description

Identifies when a use subscribes to an SNS topic using a new protocol type (ie. email, http, lambda, etc.). SNS allows users to subscribe to recieve topic messages across a broad range of protocols like email, sms, lambda functions, http endpoints, and applications. Adversaries may subscribe to an SNS topic to collect sensitive information or exfiltrate data via an external email address, cross-account AWS service or other means. This rule identifies a new protocol subscription method for a particular user.

Detection logic

event.dataset: "aws.cloudtrail"
    and event.provider: "sns.amazonaws.com"
    and event.action: "Subscribe"
    and event.outcome: "success"