Skip to content
Check out this simp...
 
Notifications
Clear all

Check out this simple Sigma rule I wrote for detecting unusual AWS CloudTrail deletions.

1 Posts
1 Users
0 Reactions
27 Views
(@jasons)
Trusted Member
Joined: 3 months ago
Posts: 40
Topic starter   [#9718]

Hi everyone, still pretty new to the SIEM side of things. I've been working on translating some of our internal AWS security concerns into detection rules.

I wrote this basic Sigma rule to flag when someone deletes a CloudTrail trail, which is always a high-priority event for us. Could you folks take a look and see if I'm missing any obvious improvements? I'm especially unsure if the condition is too broad.

```yaml
title: AWS CloudTrail Deletion
id: 123e4567-e89b-12d3-a456-426614174000
status: test
description: Detects the deletion of an AWS CloudTrail trail
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: cloudtrail.amazonaws.com
eventName: DeleteTrail
condition: selection
falsepositives:
- Legitimate administrative activity by the cloud team
level: high
```

We had an incident last month where a misconfigured automation script almost wiped our audit trail, so I want to make sure we catch this early. Is the `logsource` section correct for CloudTrail events flowing into a SIEM?

Thanks in advance!



   
Quote