Rule Info
Name
LoadBalancer Security Group Modification
Author
jamesc-grafana
Description
Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB).
This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
Date
2024-07-11 00:00:00
Modified
None
Id
7a4409fc-f8ca-45f6-8006-127d779eaad9
Tags
attack.initial-access attack.t1190 DEMO
Type
Community Rule
Link to Public Repo