mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
29 lines
1.3 KiB
YAML
29 lines
1.3 KiB
YAML
name: AWS Network ACL Activity
|
|
id: 2e8948a5-5239-406b-b56b-6c50ff268af4
|
|
version: 2
|
|
date: '2018-05-21'
|
|
author: Bhavin Patel, Splunk
|
|
description: Monitor your AWS network infrastructure for bad configurations and malicious
|
|
activity. Investigative searches help you probe deeper, when the facts warrant it.
|
|
narrative: AWS CloudTrail is an AWS service that helps you enable governance, compliance,
|
|
and operational/risk auditing of your AWS account. Actions taken by a user, role,
|
|
or an AWS service are recorded as events in CloudTrail. It is crucial for a company
|
|
to monitor events and actions taken in the AWS Management Console, AWS Command Line
|
|
Interface, and AWS SDKs and APIs to ensure that your servers are not vulnerable
|
|
to attacks. This analytic story contains detection searches that leverage CloudTrail
|
|
logs from AWS to check for bad configurations and malicious activity in your AWS
|
|
network access controls.
|
|
references:
|
|
- https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html
|
|
- https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/
|
|
tags:
|
|
analytic_story: AWS Network ACL Activity
|
|
category:
|
|
- Cloud Security
|
|
product:
|
|
- Splunk Security Analytics for AWS
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|