Techniques
Sample rules
AWS WAF Rule or Rule Group Deletion
- source: elastic
- technicques:
- T1562
Description
Identifies the deletion of a specified AWS Web Application Firewall (WAF) rule or rule group.
Detection logic
event.dataset:aws.cloudtrail and event.provider:(waf.amazonaws.com or waf-regional.amazonaws.com or wafv2.amazonaws.com) and event.action:(DeleteRule or DeleteRuleGroup) and event.outcome:success