
Summary
The VPC Endpoint Access Denied detection rule aims to identify instances where access to AWS resources is denied due to policies applied on Virtual Private Cloud (VPC) Endpoints. This can be indicative of unauthorized attempts to access services in AWS, potentially targeting sensitive data or resources. The rule is specifically designed to analyze logs captured from AWS CloudTrail, looking for events where an error condition, such as 'VpceAccessDenied', occurs. This helps in enhancing the security posture by identifying unauthorized access attempts and enforcing appropriate access controls.
Categories
- Cloud
- AWS
- Network
Data Sources
- Cloud Service
- Network Traffic
ATT&CK Techniques
- T1599
- T1526
Created: 2025-03-28