Techniques
Sample rules
AWS Route Table Modified or Deleted
- source: elastic
- technicques:
Description
Identifies when an AWS Route Table has been modified or deleted.
Detection logic
event.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:(ReplaceRoute or ReplaceRouteTableAssociation or
DeleteRouteTable or DeleteRoute or DisassociateRouteTable) and event.outcome:success