Skip to content

Commit

Permalink
adding the final batch of qa tested already existing aws cloudtrail r…
Browse files Browse the repository at this point in the history
…ules to prod (#569)
  • Loading branch information
andrea-youwakim authored Nov 30, 2022
1 parent 56bdc53 commit 4e8d8ff
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions packs/aws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@ PackDefinition:
- AWS.S3.Bucket.PolicyAllowWithNotPrincipal
- AWS.S3.Bucket.PrincipalRestrictions
- AWS.Macie.Evasion
- AWS.CloudTrail.ResourceMadePublic
- AWS.Snapshot.Backup.Exfiltration
- AWS.CloudTrail.SnapshotMadePublic
# Encryption Status
- AWS.DynamoDB.TableEncryption
- AWS.EC2.Volume.Encryption
Expand Down Expand Up @@ -50,6 +53,7 @@ PackDefinition:
# User and Account Policies and Rules
- AWS.Console.LoginWithoutMFA
- AWS.Console.LoginWithoutSAML
- AWS.Suspicious.SAML.Activity
- AWS.IAM.Entity.InlinePolicyDoesNotGrantNetworkAdminAccess
- AWS.IAM.User.MFA
- AWS.Password.Unused
Expand All @@ -60,6 +64,9 @@ PackDefinition:
- AWS.IAM.PolicyModified
- AWS.IAM.Backdoor.User.Keys
- AWS.IAMUser.ReconAccessDenied
- AWS.IAM.CredentialsUpdated
- AWS.User.Login.Profile.Modified

# General Policies and Rules
- AWS.ACM.Certificate.Valid
- AWS.CloudTrail.Created
Expand All @@ -75,9 +82,16 @@ PackDefinition:
- AWS.GuardDuty.HighSeverityFinding
- AWS.ELBV2.LoadBalancer.HasSSLPolicy
- AWS.WAF.HasXSSPredicate
- AWS.WAF.Disassociation
- AWS.EC2.Startup.Script.Change
- AWS.RDS.MasterPasswordUpdated
- AWS.RDS.PublicRestore
- AWS.S3.GreyNoiseActivity
- AWS.S3.BucketDeleted
- AWS.S3.BucketPolicyModified
- AWS.CloudTrail.SecurityConfigurationChange
- AWS.SecurityHub.Finding.Evasion
- AWS.CloudTrail.UnauthorizedAPICall
# Standard Rules applicable to AWS
- Standard.BruteForceByIP
# AWS DataModels
Expand Down

0 comments on commit 4e8d8ff

Please sign in to comment.