mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
11468edab6
* [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role - Edited Rule Name, Description, and Investigation Guide to better align with the behavior captured by this rule - adjusted execution window - added highlighted fields * adding account id to highlighted fields adding account id to highlighted fields * changing AWS EC2 tag for consistency across EC2 rules changing AWS EC2 tag for consistency across EC2 rules