New Network ACL Entry Added

 Original Source: [Sigma source]
Title: New Network ACL Entry Added
Status: test
Description:Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.
References:
  -https://www.gorillastack.com/blog/real-time-events/important-aws-cloudtrail-security-events-tracking/
Author: jamesc-grafana
Date: 2024-07-11
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686.001'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'ec2.amazonaws.com'
    eventName: 'CreateNetworkAclEntry'
  condition:selection
Falsepositives:
  -Legitimate use of ACLs to enable customer and staff access from the public internet into a public VPC
Level: low