AWS WAF web access control list modified

Goal

Detect when an AWS Web Application Firewall (WAF) Access Control List (ACL) is updated.

Strategy

The rule monitors AWS WAF logs @eventSource:waf*.amazonaws.com and detects when the @evt.name is UpdateWebACL.

Triage and response

  1. Determine if {{@userIdentity.arn}} is expected to perform the {{@evt.name}} API call on the account: {{@userIdentity.accountId}}.
  2. If the API call was not made legitimately by the user, rotate the user’s credentials and investigate what other APIs were successfully accessed.