Amazon Security Lake - CloudTrail rules grouped.


Description

Amazon Security Lake - CloudTrail rules grouped.

Query · wazuh

field metadata.product.name="CloudTrail"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=json AND field activity_id="\.+" AND field category_uid="\.+"
  2. 99001 Amazon Security Lake - CloudTrail rules grouped. anchor level 3 this rule
    field metadata.product.name="CloudTrail"

Rule dependencies

Depends on

Raw source Amazon Security Lake - CloudTrail rules grouped. · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="99001" level="3">
    <if_sid>99000</if_sid>
    <field name="metadata.product.name">CloudTrail</field>
    <description>Amazon Security Lake - CloudTrail rules grouped.</description>
    <mitre>
      <id>T1048.001</id>
    </mitre>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.