mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
25 lines
923 B
YAML
25 lines
923 B
YAML
name: AWS Security Hub Alerts
|
|
id: 2f2f610a-d64d-48c2-b57c-96722b49ab5a
|
|
version: 1
|
|
date: '2020-08-04'
|
|
author: Bhavin Patel, Splunk
|
|
description: This story is focused around detecting Security Hub alerts generated
|
|
from AWS
|
|
narrative: AWS Security Hub collects and consolidates findings from AWS security services
|
|
enabled in your environment, such as intrusion detection findings from Amazon GuardDuty,
|
|
vulnerability scans from Amazon Inspector, S3 bucket policy findings from Amazon
|
|
Macie, publicly accessible and cross-account resources from IAM Access Analyzer,
|
|
and resources lacking WAF coverage from AWS Firewall Manager.
|
|
references:
|
|
- https://aws.amazon.com/security-hub/features/
|
|
tags:
|
|
analytic_story: AWS Security Hub Alerts
|
|
category:
|
|
- Cloud Security
|
|
product:
|
|
- Splunk Security Analytics for AWS
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|