LoadBalancer Security Group Modification

 Original Source: [Sigma source]
Title: LoadBalancer Security Group Modification
Status: test
Description:Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
References:
  -https://www.gorillastack.com/blog/real-time-events/important-aws-cloudtrail-security-events-tracking/
Author: jamesc-grafana
Date: 2024-07-11
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'elasticloadbalancing.amazonaws.com'
    eventName:
      -'ApplySecurityGroupsToLoadBalancer'
      -'SetSecurityGroups'

  condition:selection
Falsepositives:
  -Repurposing of an ELB or ALB to serve a different or additional application
  -Changes to security groups to allow for new services to be deployed
Level: medium