heroui logo

Wiz Issue Alert Passthrough Rule

Panther Rules

View Source
Summary
This detection rule, named 'Wiz Issue Alert Passthrough Rule', is designed to enhance and provide context to security alerts generated by the Wiz platform. The rule examines logs coming from the 'Wiz.IssuesWebhook', which covers alerts related to potential security issues identified in cloud resources, primarily within an AWS environment. The rule has a medium severity level and works by capturing various alert scenarios, notably for open alerts with different severity levels including high and low. This allows for quick identification and response to vulnerabilities such as unprotected ports on EC2 instances. Users are advised to review the details of the generated alerts to discern the nature of the issue and take necessary actions. Each captured alert includes critical metadata about the incident such as timestamps, resource details, and severity ratings assigned dynamically by GuardDuty. Tests have been implemented to validate the functionality of the detection rule, ensuring correct response to varying alert conditions.
Categories
  • Cloud
  • AWS
  • Infrastructure
Data Sources
  • WMI
  • Sensor Health
  • Logon Session
  • Process
  • Network Traffic
Created: 2025-11-05