Support for monitoring VPC Flow Logs, S3 Access Logs, and AWS Config? #4871
-
Hello everyone, I’m exploring alternatives to AWS GuardDuty due to its cost and am considering using Sigma rules instead. I’ve noticed that the rules in the cloud/aws directory focus on CloudTrail logs. Are there existing Sigma rules I missed or didn't find for monitoring VPC Flow Logs, S3 Access Logs, and AWS Config? More specifically, I’m curious if there are any rules that help address the following:
Thank you! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hi and thanks for opening this discussion. Unfortunately the rules you found in the AWS folder are currently the only ones for AWS. As with all rules in this repo, they were contributed by the community. So apart the case where someone contributes rules for similar cases you mentioned there will be no additional rules regarding that for the moment. |
Beta Was this translation helpful? Give feedback.
Hi and thanks for opening this discussion.
Unfortunately the rules you found in the AWS folder are currently the only ones for AWS.
As with all rules in this repo, they were contributed by the community. So apart the case where someone contributes rules for similar cases you mentioned there will be no additional rules regarding that for the moment.