AWS SecurityHub Findings Evasion

 Original Source: [Sigma source]
Title: AWS SecurityHub Findings Evasion
Status: stable
Description:Detects the modification of the findings on SecurityHub.
References:
  -https://docs.aws.amazon.com/cli/latest/reference/securityhub/
Author: Sittikorn S
Date: 2021-06-28
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'securityhub.amazonaws.com'
    eventName:
      -'BatchUpdateFindings'
      -'DeleteInsight'
      -'UpdateFindings'
      -'UpdateInsight'

  condition:selection
Falsepositives:
  -System or Network administrator behaviors
  -DEV, UAT, SAT environment. You should apply this rule with PROD environment only.
Level: high