Skip to content

Commit

Permalink
adjust aws rule index patterns and tags (#3595)
Browse files Browse the repository at this point in the history
  • Loading branch information
terrancedejesus authored Apr 16, 2024
1 parent c2d1586 commit 7431279
Show file tree
Hide file tree
Showing 55 changed files with 140 additions and 134 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2024/01/05"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -14,7 +14,7 @@ used to delegate access to users or services. An adversary may attempt to enumer
role exists before attempting to assume or hijack the discovered role.
"""
from = "now-20m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
language = "kuery"
license = "Elastic License v2"
name = "AWS IAM Brute Force of Assume Role Policy"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -18,7 +18,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2024/03/07"
updated_date = "2024/04/14"

[rule]
author = ["Nick Jones", "Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws.cloudtrail*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2024/01/05"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-20m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
language = "kuery"
license = "Elastic License v2"
name = "AWS Management Console Brute Force of Root User Identity"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -21,7 +21,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic", "Austin Songer"]
Expand All @@ -21,7 +21,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Austin Songer"]
Expand All @@ -18,7 +18,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Austin Songer"]
Expand All @@ -18,7 +18,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Austin Songer"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-25m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
language = "kuery"
license = "Elastic License v2"
name = "AWS SAML Activity"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
4 changes: 2 additions & 2 deletions rules/integrations/aws/defense_evasion_waf_acl_deletion.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -17,7 +17,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic", "Austin Songer"]
Expand All @@ -21,7 +21,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic"]
Expand All @@ -20,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ integration = ["aws"]
maturity = "production"
min_stack_comments = "AWS integration breaking changes, bumping version to ^2.0.0"
min_stack_version = "8.9.0"
updated_date = "2023/10/24"
updated_date = "2024/04/14"

[rule]
author = ["Elastic", "Austin Songer"]
description = """
Expand All @@ -19,7 +20,7 @@ false_positives = [
""",
]
from = "now-60m"
index = ["filebeat-*", "logs-aws*"]
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
interval = "10m"
language = "kuery"
license = "Elastic License v2"
Expand Down
Loading

0 comments on commit 7431279

Please sign in to comment.