cscli scenarios install crowdsecurity/aws-cis-benchmark-ngw-change
Detects AWS Network Gateway changes based on cloudtrail logs (Section 4.12 of CIS AWS Foundation Benchmark 1.4.0 ).
1type: trigger2name: crowdsecurity/aws-cis-benchmark-ngw-change3description: "Detect AWS Network Gateway change"4filter: |5 evt.Meta.log_type == 'aws-cloudtrail' &&6 (7 evt.Meta.event_name == "CreateCustomerGateway" ||8 evt.Meta.event_name == "DeleteCustomerGateway" ||9 evt.Meta.event_name == "AttachInternetGateway" ||10 evt.Meta.event_name == "CreateInternetGateway" ||11 evt.Meta.event_name == "DeleteInternetGateway" ||12 evt.Meta.event_name == "DetachInternetGateway"13 )14labels:15 confidence: 316 spoofable: 017 classification:18 - attack.T157819 behavior: "cloud:audit"20 label: "AWS Network Gateway change"21 service: aws22 cti: false23 remediation: false24