Title:
AWS SecurityHub Findings Evasion
Status:
stable
Description:Detects the modification of the findings on SecurityHub.
References:
-https://docs.aws.amazon.com/cli/latest/reference/securityhub/
Author: Sittikorn S
Date: 2021-06-28
modified:None
Tags:
- -'attack.defense-impairment'
- -'attack.t1685'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
eventSource:
'securityhub.amazonaws.com'
eventName:
-'BatchUpdateFindings'
-'DeleteInsight'
-'UpdateFindings'
-'UpdateInsight'
condition:
selection
Falsepositives:
-System or Network administrator behaviors
-DEV, UAT, SAT environment. You should apply this rule with PROD environment only.
Level:
high