Hi everyone, still pretty new to the SIEM side of things. I've been working on translating some of our internal AWS security concerns into detection rules.
I wrote this basic Sigma rule to flag when someone deletes a CloudTrail trail, which is always a high-priority event for us. Could you folks take a look and see if I'm missing any obvious improvements? I'm especially unsure if the condition is too broad.
```yaml
title: AWS CloudTrail Deletion
id: 123e4567-e89b-12d3-a456-426614174000
status: test
description: Detects the deletion of an AWS CloudTrail trail
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: cloudtrail.amazonaws.com
eventName: DeleteTrail
condition: selection
falsepositives:
- Legitimate administrative activity by the cloud team
level: high
```
We had an incident last month where a misconfigured automation script almost wiped our audit trail, so I want to make sure we catch this early. Is the `logsource` section correct for CloudTrail events flowing into a SIEM?
Thanks in advance!