cscli scenarios install crowdsecurity/aws-cis-benchmark-vpc-change
Detects AWS VPC changes based on cloudtrail logs (Section 4.14 of CIS AWS Foundation Benchmark 1.4.0 ).
1type: trigger2name: crowdsecurity/aws-cis-benchmark-vpc-change3description: "Detect AWS VPC change"4filter: |5 evt.Meta.log_type == 'aws-cloudtrail' &&6 (7 evt.Meta.event_name == "CreateVpc" ||8 evt.Meta.event_name == "DeleteVpc" ||9 evt.Meta.event_name == "ModifyVpcAttribute" ||10 evt.Meta.event_name == "AcceptVpcPeeringConnection" ||11 evt.Meta.event_name == "CreateVpcPeeringConnection" ||12 evt.Meta.event_name == "DeleteVpcPeeringConnection" ||13 evt.Meta.event_name == "RejectVpcPeeringConnection" ||14 evt.Meta.event_name == "AttachClassicLinkVpc" ||15 evt.Meta.event_name == "DetachClassicLinkVpc" ||16 evt.Meta.event_name == "DisableVpcClassicLink" ||17 evt.Meta.event_name == "EnableVpcClassicLink"18 )19labels:20 confidence: 321 spoofable: 022 classification:23 - attack.T157824 behavior: "cloud:audit"25 label: "AWS VPC change"26 service: aws27 cti: false28 remediation: false29