Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 976 Bytes

THRESHOLD-S00106.md

File metadata and controls

36 lines (29 loc) · 976 Bytes

Rules: AWS Image Discovery

Description

Detects various describe and/or list commands used for an image in AWS.

Additional Details

Detail Value
Type Threshold
Category Discovery
Apply Risk to Entities srcDevice_ip, device_ip, user_username
Signal Name AWS Image Discovery
Summary Expression AWS Image Discovery Detected with IP: {{srcDevice_ip}} and User: {{user_username}}
Threshold Count 3
Threshold Window 5m
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1526

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema device_ip
Normalized Schema listMatches
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username