AWS ECS cluster deleted

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when an attacker is destroying an ECS Cluster

Strategy

This rule lets you monitor this CloudTrail API call to detect if an ECS cluster is deleted:

Triage and response

  1. Determine if {{@userIdentity.arm}} should be making a {{@evt.name}} API call.
  2. Contact the user to see if they intended to make this API call.
  3. If the user did not make the API call:
    • Rotate the credentials.
    • Investigate if the same credentials made other unauthorized API calls.

Changelog

1 April 2022 - Updated rule query.