LoadBalancer Security Group Modification

Rule Info

Name
LoadBalancer Security Group Modification
Author
jamesc-grafana
Description
Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
Date
2024-07-11 00:00:00
Modified
None
Id
7a4409fc-f8ca-45f6-8006-127d779eaad9
Tags
attack.initial-access attack.t1190 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
James C
Merge PR #4900 from @jamesc-grafana - Add new AWS cloudtrail rules
2024-07-11