New

The executive guide to generative AI

Read more

AWS ElastiCache Security Group Modified or Deleted

edit

AWS ElastiCache Security Group Modified or Deleted

edit

Identifies when an ElastiCache security group has been modified or deleted.

Rule type: query

Rule indices:

  • filebeat-*
  • logs-aws*

Severity: low

Risk score: 21

Runs every: 10m

Searches indices from: now-60m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Elastic
  • Cloud
  • AWS
  • Amazon Web Services
  • Continuous Monitoring
  • SecOps
  • Monitoring

Version: 102

Rule authors:

  • Austin Songer

Rule license: Elastic License v2

Investigation guide

edit

Rule query

edit
event.dataset:aws.cloudtrail and event.provider:elasticache.amazonaws.com and event.action:("Delete Cache Security Group" or
"Authorize Cache Security Group Ingress" or  "Revoke Cache Security Group Ingress" or "AuthorizeCacheSecurityGroupEgress" or
"RevokeCacheSecurityGroupEgress") and event.outcome:success

Framework: MITRE ATT&CKTM

Was this helpful?
Feedback