Merge pull request #1977 from rachelrice/update_aws_assumerole

Update AWS STS AssumeRole Misuse rule
This commit is contained in:
frack113 2021-09-03 08:11:52 +02:00 committed by GitHub
commit b0f8275f72
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -12,8 +12,7 @@ logsource:
service: cloudtrail
detection:
selection:
eventSource: sts.amazonaws.com
eventName: AssumeRole
userIdentity.type: AssumedRole
userIdentity.sessionContext.sessionIssuer.type: Role
condition: selection
level: low