Skip to content

Commit 653399e

Browse files
removed protocol inclusion in query
1 parent e7a627c commit 653399e

File tree

2 files changed

+2
-3
lines changed

2 files changed

+2
-3
lines changed

detection_rules/etc/non-ecs-schema.json

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -150,8 +150,7 @@
150150
"logs-aws.cloudtrail-*": {
151151
"aws.cloudtrail.flattened.request_parameters.cidrIp": "keyword",
152152
"aws.cloudtrail.flattened.request_parameters.fromPort": "keyword",
153-
"aws.cloudtrail.flattened.request_parameters.roleArn": "keyword",
154-
"aws.cloudtrail.request_parameters.protocol": "keyword"
153+
"aws.cloudtrail.flattened.request_parameters.roleArn": "keyword"
155154
},
156155
"logs-azure.signinlogs-*": {
157156
"azure.signinlogs.properties.conditional_access_audiences.application_id": "keyword"

rules/integrations/aws/exfiltration_sns_email_subscription_by_rare_user.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ query = '''
7878
event.dataset: "aws.cloudtrail"
7979
and event.provider: "sns.amazonaws.com"
8080
and event.action: "Subscribe"
81-
and aws.cloudtrail.request_parameters.protocol: "email"
81+
and aws.cloudtrail.request_parameters: *protocol=email*
8282
'''
8383

8484

0 commit comments

Comments
 (0)