Alerts related to data source "AWS Audit Log".
A Backup vault policy was modified
A cloud function was created with an unusual runtime
A cloud identity created or modified a security group
A cloud identity executed an API call from an unusual country
A cloud identity had escalated its permissions
A cloud identity invoked IAM related persistence operations
A cloud identity performed multiple unusual activities
A cloud identity started a Cloud Shell session
A cloud instance was stopped
A cloud snapshot of AWS database or storage was modified or shared
A cloud storage configuration was modified
A cloud storage object was copied to a foreign cloud account
A Command Line Interface (CLI) command was executed from an AWS serverless compute service
A compute-attached identity executed API calls outside the instance's region
A container registry was created or deleted
A Kubernetes API operation was successfully invoked by an anonymous user
A Kubernetes cluster role binding was created or deleted
A Kubernetes cluster role was created
A Kubernetes cluster was created or deleted
A Kubernetes ConfigMap was created or deleted
A Kubernetes Cronjob was created
A Kubernetes DaemonSet was created
A Kubernetes dashboard service account was used outside the cluster
A Kubernetes deployment was created
A Kubernetes ephemeral container was created
A Kubernetes namespace was created or deleted
A Kubernetes node service account activity from external IP
A Kubernetes Pod was created with a sidecar container
A Kubernetes Pod was deleted
A Kubernetes ReplicaSet was created
A Kubernetes role binding was created or deleted
A Kubernetes secret was created or deleted
A Kubernetes service account executed an unusual API call
A Kubernetes service account has enumerated its permissions
A Kubernetes service account was created or deleted
A Kubernetes service was created or deleted
A Kubernetes StatefulSet was created
A user logged in to the AWS console for the first time
Abnormal Allocation of compute resources in multiple regions
AI model discovery
AI safeguards deletion attempt
AI safeguards were modified
Allocation of multiple cloud compute resources
An AWS database service master user password was changed
An AWS EC2 instance containing sensitive data was exported
An AWS EC2 instance was exported from a production account
An AWS EC2 instance was exported into an unknown S3 bucket
An AWS EFS File-share mount was deleted
An AWS EFS file-share was deleted
An AWS EKS cluster was created or deleted
An AWS GuardDuty IP set was created
An AWS Lambda Function was created
An AWS Lambda function was modified
An AWS RDS Global Cluster Deletion
An AWS RDS instance was created from a snapshot
An AWS Route 53 domain was transferred to another AWS account
An AWS S3 bucket configuration was modified
An AWS SAML provider was modified
An AWS SES identity was deleted
An EBS snapshot block was downloaded
An Email address was added to AWS SES
An IAM group was created
An identity accessed a backup cloud storage
An identity accessed a cloud storage for the first time
An identity attached an administrative policy to an IAM user or role
An identity created or updated password for an IAM user
An identity disabled bucket logging
An identity initiated a download of multiple cloud objects
An identity performed a suspicious download of multiple cloud storage objects
An identity started an AWS SSM session
An identity successfully extracted multiple secrets within the organization
An operation was performed by an identity from a domain that was not seen in the organization
An RDS snapshot containing sensitive data was exported
An RDS snapshot was exported from a production account
An RDS snapshot was exported to an unknown bucket
An RDS snapshot was exported to an unknown S3 bucket
An S3 replication policy to an unknown bucket was created
An unknown account was invited to the AWS organization
An unusual read activity of cloud object
Aurora DB cluster stopped
AWS Backup recovery point deletion
AWS Backup vault was deleted
AWS Bedrock AI infrastructure enumeration activity
AWS Bedrock model invocation logging deletion
AWS CloudTrail has been stopped
AWS CloudTrail modification
AWS CloudWatch log group deletion
AWS CloudWatch log stream deletion
AWS Config Recorder stopped
AWS config resource deletion
AWS console login without MFA
AWS data asset shared public
AWS EBS enumeration activity
AWS EBS snapshot deletion
AWS EC2 infrastructure enumeration activity
AWS EC2 instance exported into S3
AWS Flow Logs deletion
AWS Guard-Duty detector deletion
AWS IAM resource group deletion
AWS IAM Role Created with Cross-Account Access
AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access
AWS Lambda Cross-Account sensitive permissions configured
AWS Lambda infrastructure enumeration activity
AWS network ACL rule creation
AWS network ACL rule deletion
AWS Password Policy Discovery
AWS principals discovery
AWS RDS cluster deletion
AWS resource discovery
AWS root account activity
AWS Route53 DNS Resolver query logging configuration deletion
AWS S3 bucket data retention policy change through S3 Lifecycle rule
AWS S3 bucket was exposed to public access
AWS S3 Buckets enumeration activity
AWS Secrets Manager discovery
AWS Security Group remote access allowed from an unknown external IP address
AWS Security Service Enumeration
AWS SecurityHub findings were modified
AWS SES account sending settings modified
AWS SSM association created with inventory collection document
AWS SSM parameters discovery
AWS SSM parameters retrieval
AWS SSM send command attempt
AWS Storage Gateway enumeration
AWS Storage Gateway file share enumeration
AWS STS temporary credentials were generated
AWS support case creation
AWS Systems Manager hosts enumeration
AWS Transfer Family server created
AWS user creation
AWS web ACL deletion
Bedrock model shared with a foreign account
Billing admin role was removed
Bucket's block public access setting turned off
Bucket's object ownership controls were modified
Cloud access key creation
Cloud activity from a high-risk IP address
Cloud AI agent was modified
Cloud compute instance user data script modification
Cloud compute serial console access
Cloud compute volume creation attempt
Cloud email infrastructure enumeration activity
Cloud email sending was enabled
Cloud email service activity
Cloud identity reached a throttling API rate
Cloud IMDS access followed by remote token usage
Cloud impersonation attempt by unusual identity type
Cloud infrastructure discovery across multiple regions
Cloud infrastructure enumeration activity
Cloud instance creation attempt
Cloud instance deletion attempt
Cloud penetration testing tool activity
Cloud snapshot created or modified
Cloud snapshot of a database or storage instance was publicly shared
Cloud storage automatic backup disabled
Cloud storage delete protection disabled
Cloud user performed multiple actions that were denied
Cloud Watch alarm deletion
CloudTrail logging deletion
Command execution via AWS SSM
Compute activity in dormant cloud region
Data encryption was disabled
Deletion of multiple cloud resources
Denied API call by a Kubernetes service account
Disable AWS audit logs through Event Selectors
Disable encryption operations
EBS snapshots were created from an EC2 instance
EBS volume attachment attempt
EBS volume detachment attempt
EC2 backdoor created with newly added external SSH or RDP access
EC2 instance Amazon machine image was created
Foreign account was granted permissions to S3 bucket via resource-based policy
IAM Enumeration sequence
IAM inline policy was added to group
IAM inline policy was added to role
IAM inline policy was added to user
IAM instance profile associations were described
IAM instance profile was associated with EC2 instance
IAM instance profile was created
IAM instance profile was replaced for EC2 instance
IAM policy default version was changed
IAM policy version was created
IAM policy was attached to group
IAM policy was attached to role
IAM role trust policy modification
IAM role was created
IAM role-attached managed policies were listed
IAM User added to an IAM group
Impossible travel by a cloud identity
KMS key policy was changed
Kubernetes admission controller activity
Kubernetes cluster events deletion
Kubernetes enumeration activity
Kubernetes network policy modification
Kubernetes Pod Created with host Inter Process Communications (IPC) namespace
Kubernetes Pod created with host process ID (PID) namespace
Kubernetes Pod Created With Sensitive Volume
Kubernetes pod creation from unknown container image registry
Kubernetes pod creation with host network
Kubernetes Privileged Pod Creation
Kubernetes secrets enumeration for the first time
Kubernetes service account activity outside the cluster
Kubernetes vulnerability scanning tool usage
Log enumeration via cloud native logging service
Logging was impaired via external encryption key
Mass deletion of versioned S3 objects
MFA device was removed/deactivated from an IAM user
ML artifacts destruction
Multi region enumeration activity
Multiple cloud snapshots export
Multiple failed AWS assume role attempts
Multiple failed logins from a single IP
Multiple risk indicators for a cloud identity
Network sniffing detected in Cloud environment
New cloud identity created with administrative policy
Object versioning was disabled
Potential creation of persistent cloud credentials
Potential denial of wallet abusing AI services
Remote usage of an AWS service token
Remote usage of AWS Lambda's role
Retrieval of cloud compute EC2 instance user data
S3 configuration deletion
Serial console access was enabled in AWS account
SES Production Access Requested
Storage enumeration activity
Suspicious activity indicating a potential abuse of a cloud-native email service
Suspicious activity on logging bucket
Suspicious AI Dataset Download
Suspicious AI Dataset Label Modification
Suspicious AI model usage from a Tor exit node
Suspicious API call from a Tor exit node
Suspicious AWS SSM parameters retrieval activity
Suspicious cloud compute instance SSH keys modification attempt
Suspicious cloud user data modification attempt followed by VM restart
Suspicious EBS snapshots deletion
Suspicious heavy allocation of compute resources - possible mining activity
Suspicious identity downloaded multiple objects from a bucket
Suspicious ML Model Download
Suspicious objects encryption in an AWS bucket
Suspicious secrets dump activity
Suspicious usage of EC2 token
Unusual AI dataset modification
Unusual AI Knowledge Base Modification
Unusual AI model invocation
Unusual AI RAG Knowledge Base Modification
Unusual AWS Bedrock model access request
Unusual AWS CLI/SDK activity
Unusual AWS S3 objects deletion
Unusual AWS SageMaker notebook access
Unusual AWS systems manager activity
Unusual certificate management activity
Unusual cloud identity impersonation
Unusual cross projects activity
Unusual exec into a Kubernetes Pod
Unusual Identity and Access Management (IAM) activity
Unusual key management activity
Unusual Kubernetes secret access
Unusual multi-region AWS Resource Explorer searches
Unusual resource modification by newly seen IAM user
Unusual secret management activity
Unusual user-agent for a cloud identity
Was this helpful?