
Summary
The rule 'AWS Config Service Created' detects the creation of an AWS Config Recorder or Delivery Channel using AWS CloudTrail logs. This detection is critical as it helps ensure that changes to configuration management are authorized, preventing potential misconfigurations or unauthorized access to resource management. The rule triggers an alert when a specific event named 'PutDeliveryChannel' is recorded, indicating that a new delivery channel has been created. The rule outputs various attributes relevant to the event, such as the event name, user agent, source IP address, and recipient account ID. Additionally, it includes test cases that validate expected behaviors when the delivery channel is created or deleted, ensuring the integrity and security of the configuration service deployment.
Categories
- Cloud
- AWS
- Other
Data Sources
- Cloud Storage
- Logon Session
- Application Log
- Network Traffic
- Network Share
ATT&CK Techniques
- T1526
Created: 2022-09-02