LoFP LoFP / valid changes to the startup script

Techniques

Sample rules

AWS EC2 Startup Shell Script Change

Description

Detects changes to the EC2 instance startup script. The shell script will be executed as root/SYSTEM every time the specific instances are booted up.

Detection logic

condition: selection_source
selection_source:
  eventName: ModifyInstanceAttribute
  eventSource: ec2.amazonaws.com
  requestParameters.attribute: userData