Files
elastic-detection-rules/rules/integrations
Isai 3a53e96ecd [Rule Tuning] AWS IAM CompromisedKeyQuarantine Policy Attached to User (#5281)
This rule is working as expected, only instances of this alert in telemetry is for testing environments.
- uses `iam` instead of `any` for eql query
- added highlighted fields

(cherry picked from commit 37f28be816)
2025-11-17 21:27:15 +00:00
..
2025-07-07 15:30:11 +00:00
2025-03-20 15:07:35 +00:00
2025-07-07 15:30:11 +00:00