New Network ACL Entry Added
Description
Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.
Query · sigma
selection: eventSource: ec2.amazonaws.com eventName: CreateNetworkAclEntry condition: selection
Known false positives
- Legitimate use of ACLs to enable customer and staff access from the public internet into a public VPC