Aws:SecurityManagement:EventBridge-Others
(書きかけ)93.EventBridge
「ログメトリクスフィルターとアラームが存在すること」系をEventBridgeに置き換えられないか検討してみた。
発見的対策
- EventsBridgeSampleTemplate
-
AWSTemplateFormatVersion: 2010-09-09
対応項目
{
"source": ["aws.securityhub"],
"detail-type": ["Security Hub Findings - Imported"],
"detail": {
"findings": {
"Compliance": {
"Status": [{
"anything-but": "PASSED"
}]
},
"RecordState": ["ACTIVE"],
"Resources": {
"Type": [{
"anything-but": "AwsAccount"
}]
},
"Workflow": {
"Status": ["NEW"]
}
}
}
}
{
"source": [
"aws.access-analyzer"
],
"detail-type": [
"Access Analyzer Finding","Access Preview State Change"
]
}
{
"source": [
"aws.guardduty"
],
"detail": {
"type": [
"UnauthorizedAccess:EC2/MaliciousIPCaller.Custom"
]
}
}
追加したConfigルールのチェック
{
"detail": {
"eventSource": [
"config.amazonaws.com"
],
"eventName": [
"PutEvaluations"
],
"requestParameters": {
"evaluations": {
"complianceType": [
"NON_COMPLIANT"
]
}
},
"additionalEventData": {
"managedRuleIdentifier": ["LAMBDA_INSIDE_VPC","EIP_ATTACHED","CLOUD_TRAIL_ENABLED"]
}
}
}
Aws/SecurityManagement/EventBridge-Others.txt · 最終更新: by admin
コメント