LoFP LoFP / valid change in a trail

Techniques

Sample rules

AWS CloudTrail Important Change

Description

Detects disabling, deleting and updating of a Trail

Detection logic

condition: selection_source
selection_source:
  eventName:
  - StopLogging
  - UpdateTrail
  - DeleteTrail
  eventSource: cloudtrail.amazonaws.com