Files
elastic-detection-rules/rules/integrations
Isai 6878d4e7a9 [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role (#4774)
* [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role

- Edited Rule Name, Description, and Investigation Guide to better align with the behavior captured by this rule
- adjusted execution window
- added highlighted fields

* adding account id to highlighted fields

adding account id to highlighted fields

* changing AWS EC2 tag for consistency across EC2 rules

changing AWS EC2 tag for consistency across EC2 rules

(cherry picked from commit 11468edab6)
2025-06-06 19:13:38 +00:00
..
2025-03-20 15:07:35 +00:00
2025-03-20 15:07:35 +00:00
2025-03-19 20:27:30 -04:00
2025-03-26 15:08:47 +00:00