Custom Detection Rules finding types
This page lists all finding types that GuardDuty generates from Custom Detection Rules. Each finding type aggregates one or more signals into a single finding. For more information about enabling Custom Detection Rules, see Custom Detection Rules in GuardDuty.
Note
The availability of individual rules depends on the availability of the corresponding AWS service and feature in each Region. For example, rules that target AWS Organizations or Amazon Simple Email Service are available only in Regions where those services operate. Similarly, rules that target Lambda function URLs or SageMaker AI notebook instances are available only in Regions where those features are supported.
AWS CloudTrail Management Events
The following finding types are generated from AWS CloudTrail management event signals, organized by MITRE ATT&CKĀ® tactic.
Credential Access
Attempts to steal credentials such as passwords, tokens, or keys.
Finding type |
Signal name |
Severity |
|---|---|---|
CredentialAccess:EC2/UnsecuredCredentials |
MEDIUM |
|
CredentialAccess:RDS/ModifyAuthenticationProcess |
HIGH |
Defense Impairment
Attempts to disable or degrade security defenses.
Finding type |
Signal name |
Severity |
|---|---|---|
DefenseImpairment:EC2/DisableOrModifyTools |
LOW |
|
HIGH |
||
DefenseImpairment:Organizations/ModifyCloudResourceHierarchy |
HIGH |
|
DefenseImpairment:Organizations/DisableOrModifyTools |
HIGH |
|
DefenseImpairment:RDS/ModifyAuthenticationProcess |
MEDIUM |
|
DefenseImpairment:Route53Resolver/DisableOrModifyTools |
MEDIUM |
|
DefenseImpairment:S3/DisableOrModifyTools |
HIGH |
Execution
Attempts to run malicious code.
Finding type |
Signal name |
Severity |
|---|---|---|
Execution:SageMaker/CommandAndScriptingInterpreter |
MEDIUM |
Exfiltration
Attempts to steal data from your environment.
Finding type |
Signal name |
Severity |
|---|---|---|
Exfiltration:EC2/TransferDataToCloudAccount |
HIGH |
|
HIGH |
||
Exfiltration:RDS/TransferDataToCloudAccount |
HIGH |
|
Exfiltration:S3/TransferDataToCloudAccount |
HIGH |
Impact
Attempts to manipulate, interrupt, or destroy data and resources.
Finding type |
Signal name |
Severity |
|---|---|---|
Impact:S3/DataDestruction |
MEDIUM |
|
Impact:SES/ResourceHijacking |
LOW |
|
MEDIUM |
Initial Access
Attempts to gain entry to your environment.
Finding type |
Signal name |
Severity |
|---|---|---|
InitialAccess:IAM/ValidAccounts |
MEDIUM |
|
InitialAccess:RDS/ExploitPublicFacingApplication |
HIGH |
Lateral Movement
Attempts to move through your environment.
Finding type |
Signal name |
Severity |
|---|---|---|
LateralMovement:EC2/RemoteServices |
MEDIUM |
Persistence
Attempts to maintain access to your environment.
Finding type |
Signal name |
Severity |
|---|---|---|
Persistence:EC2/BootOrLogonInitializationScripts |
HIGH |
|
Persistence:EC2/ExternalRemoteServices |
MEDIUM |
|
Persistence:IAM/AccountManipulation |
LOW |
|
MEDIUM |
||
HIGH |
||
MEDIUM |
||
Persistence:Lambda/AccountManipulation |
HIGH |
|
Persistence:Lambda/ModifyAuthenticationProcess |
HIGH |
|
Persistence:RolesAnywhere/AccountManipulation |
MEDIUM |
Privilege Escalation
Attempts to gain higher-level permissions.
Finding type |
Signal name |
Severity |
|---|---|---|
PrivilegeEscalation:IAM/AccountManipulation |
HIGH |
|
HIGH |
||
MEDIUM |
||
MEDIUM |
||
MEDIUM |
Resource Development
Attempts to establish resources for future attacks.
Finding type |
Signal name |
Severity |
|---|---|---|
ResourceDevelopment:SES/CompromiseAccounts |
MEDIUM |