Skip to content

Commit 836a812

Browse files
adding source address
1 parent 09d8186 commit 836a812

7 files changed

+10
-2
lines changed

rules/integrations/aws/discovery_new_terms_sts_getcalleridentity.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,7 @@ event.dataset: "aws.cloudtrail"
104104
field_names = [
105105
"@timestamp",
106106
"user.name",
107+
"source.address",
107108
"aws.cloudtrail.user_identity.type",
108109
"aws.cloudtrail.user_identity.arn",
109110
"user_agent.original",

rules/integrations/aws/execution_ssm_command_document_created_by_rare_user.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,7 @@ event.dataset: "aws.cloudtrail"
8787
field_names = [
8888
"@timestamp",
8989
"user.name",
90+
"source.address",
9091
"aws.cloudtrail.user_identity.arn",
9192
"aws.cloudtrail.user_identity.type",
9293
"user_agent.original",

rules/integrations/aws/exfiltration_sns_email_subscription_by_rare_user.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,6 +85,7 @@ event.dataset: "aws.cloudtrail"
8585
field_names = [
8686
"@timestamp",
8787
"user.name",
88+
"source.address",
8889
"aws.cloudtrail.user_identity.arn",
8990
"aws.cloudtrail.user_identity.type",
9091
"user_agent.original",

rules/integrations/aws/persistence_iam_create_user_via_assumed_role_on_ec2_instance.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,7 @@ event.dataset: "aws.cloudtrail"
100100
field_names = [
101101
"@timestamp",
102102
"user.name",
103+
"source.address",
103104
"aws.cloudtrail.user_identity.arn",
104105
"aws.cloudtrail.user_identity.type",
105106
"user_agent.original",

rules/integrations/aws/persistence_iam_user_created_access_keys_for_another_user.toml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,8 +111,8 @@ from logs-aws.cloudtrail-* metadata _id, _version, _index
111111
event.action,
112112
event.outcome,
113113
user.name,
114+
source.address,
114115
user.target.name,
115-
related.user,
116116
user_agent.original,
117117
aws.cloudtrail.request_parameters,
118118
aws.cloudtrail.response_elements,
@@ -124,6 +124,7 @@ from logs-aws.cloudtrail-* metadata _id, _version, _index
124124
field_names = [
125125
"@timestamp",
126126
"user.name",
127+
"source.address",
127128
"aws.cloudtrail.user_identity.arn",
128129
"aws.cloudtrail.user_identity.type",
129130
"user_agent.original",

rules/integrations/aws/privilege_escalation_iam_administratoraccess_policy_attached_to_user.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -115,13 +115,15 @@ from logs-aws.cloudtrail-* metadata _id, _version, _index
115115
aws.cloudtrail.user_identity.arn,
116116
related.user,
117117
user_agent.original,
118-
user.name
118+
user.name,
119+
source.address
119120
'''
120121

121122
[rule.investigation_fields]
122123
field_names = [
123124
"@timestamp",
124125
"user.name",
126+
"source.address",
125127
"aws.cloudtrail.user_identity.arn",
126128
"user_agent.original",
127129
"target.userName",

rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,7 @@ event.dataset: "aws.cloudtrail"
101101
field_names = [
102102
"@timestamp",
103103
"user.name",
104+
"source.address",
104105
"aws.cloudtrail.user_identity.arn",
105106
"aws.cloudtrail.user_identity.type",
106107
"user_agent.original",

0 commit comments

Comments
 (0)