Techniques
Sample rules
Spike in AWS Error Messages
- source: elastic
- technicques:
Description
A machine learning job detected a significant spike in the rate of a particular error in the CloudTrail messages. Spikes in error messages may accompany attempts at privilege escalation, lateral movement, or discovery.
Detection logic