AWS Network Gateway created or modified

cloudtrail

Classification:

compliance

Framework:

cis-aws

Control:

4.12

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when an AWS Network Gateway has been created or modified.

Strategy

Monitor CloudTrail and detect when an AWS Network Gateway has been created or modified with one of the following API calls:

Triage and response

  1. Determine if the API call: {{@evt.name}} should have occurred.
  2. If it shouldn’t have been made:
    • Contact the user: {{@userIdentity.arn}} and see if they made the API call.
  3. If the API call was not made by the user:
    • Rotate the user credentials.
    • Determine what other API calls were made with the old credentials that were not made by the user.

Changelog

6 April 2022 - Updated rule cases and signal message.