Title:
LoadBalancer Security Group Modification
Status:
test
Description:Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB).
This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
References:
-https://www.gorillastack.com/blog/real-time-events/important-aws-cloudtrail-security-events-tracking/
Author: jamesc-grafana
Date: 2024-07-11
modified:None
Tags:
- -'attack.initial-access'
- -'attack.t1190'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
eventSource:
'elasticloadbalancing.amazonaws.com'
eventName:
-'ApplySecurityGroupsToLoadBalancer'
-'SetSecurityGroups'
condition:
selection
Falsepositives:
-Repurposing of an ELB or ALB to serve a different or additional application
-Changes to security groups to allow for new services to be deployed
Level:
medium