Rules Contributing to Suspicious AWS EBS Activity Alert
The following rules are used to identify suspicious AWS EBS activity. Any one or more of these will trigger Suspicious AWS EBS Activity Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
EBS Snapshot Created |
A copy of an EBS volume has been created. More details
Rule IDQuery{'selection1': {'eventSource': 'ec2.amazonaws.com'}, 'selection2': {'eventName': 'CreateSnapshots'}, 'selection3': {'eventName': 'BackupEBSVolume'}, 'condition': 'selection1 and (selection2 or selection3)'} Log SourceStellar Cyber AWS configured. Rule SourceDeveloped internally by Stellar Cyber Tactics, Techniques, and ProceduresReferences
N/A
Additional Information
|