AWS SecurityHub Findings Evasion
Description
Detects the modification of the findings on SecurityHub.
Query · sigma
selection: eventSource: securityhub.amazonaws.com eventName: - BatchUpdateFindings - DeleteInsight - UpdateFindings - UpdateInsight condition: selection
Known false positives
- System or Network administrator behaviors
- DEV, UAT, SAT environment. You should apply this rule with PROD environment only.