AWS WAF web access control list modified

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when an AWS Web Application Firewall (WAF) Access Control List (ACL) is updated.

Strategy

The rule monitors AWS WAF logs @eventSource:waf*.amazonaws.com and detects when the @evt.name is UpdateWebACL.

Triage and response

  1. Determine if {{@userIdentity.arn}} is expected to perform the {{@evt.name}} API call on the account: {{@userIdentity.accountId}}.
  2. If the API call was not made legitimately by the user, rotate the user’s credentials and investigate what other APIs were successfully accessed.