mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Merge pull request #1977 from rachelrice/update_aws_assumerole
Update AWS STS AssumeRole Misuse rule
This commit is contained in:
commit
b0f8275f72
@ -12,8 +12,7 @@ logsource:
|
||||
service: cloudtrail
|
||||
detection:
|
||||
selection:
|
||||
eventSource: sts.amazonaws.com
|
||||
eventName: AssumeRole
|
||||
userIdentity.type: AssumedRole
|
||||
userIdentity.sessionContext.sessionIssuer.type: Role
|
||||
condition: selection
|
||||
level: low
|
||||
|
Loading…
Reference in New Issue
Block a user