EC2 Instance Started With Previously Unseen User: endpointAWS Instancerisk_score:252024-10-17version:4
This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the latest Change Datamodel.
Abnormally High AWS Instances Launched by User: networkAWS Instancerisk_score:252024-10-17version:4
This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel
EC2 Instance Started With Previously Unseen AMI: endpointAWS Instancerisk_score:252024-10-17version:3
This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change Datamodel.
EC2 Instance Started With Previously Unseen Instance Type: endpointAWS Instancerisk_score:252024-10-17version:4
This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest Change Datamodel.
EC2 Instance Started In Previously Unseen Region: networkAWS Instancerisk_score:252024-10-17version:3
This search looks for AWS CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file of previously seen regions where an instance was started
Abnormally High AWS Instances Launched by User - MLTK: networkAWS Instancerisk_score:252024-10-17version:4
This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel.