View a markdown version of this page

Custom Detection Rules finding types - Amazon GuardDuty

Custom Detection Rules finding types

This page lists all finding types that GuardDuty generates from Custom Detection Rules. Each finding type aggregates one or more signals into a single finding. For more information about enabling Custom Detection Rules, see Custom Detection Rules in GuardDuty.

Note

The availability of individual rules depends on the availability of the corresponding AWS service and feature in each Region. For example, rules that target AWS Organizations or Amazon Simple Email Service are available only in Regions where those services operate. Similarly, rules that target Lambda function URLs or SageMaker AI notebook instances are available only in Regions where those features are supported.

AWS CloudTrail Management Events

The following finding types are generated from AWS CloudTrail management event signals, organized by MITRE ATT&CKĀ® tactic.

Credential Access

Attempts to steal credentials such as passwords, tokens, or keys.

Finding type

Signal name

Severity

CredentialAccess:EC2/UnsecuredCredentials

EC2PasswordDataRetrieved

MEDIUM

CredentialAccess:RDS/ModifyAuthenticationProcess

RDSMasterPasswordReset

HIGH

Defense Impairment

Attempts to disable or degrade security defenses.

Finding type

Signal name

Severity

DefenseImpairment:EC2/DisableOrModifyTools

EC2TerminationProtectionEnabled

LOW

VPCFlowLogsDeleted

HIGH

DefenseImpairment:Organizations/ModifyCloudResourceHierarchy

OrganizationLeaveAttempt

HIGH

DefenseImpairment:Organizations/DisableOrModifyTools

OrganizationPolicyDisabled

HIGH

DefenseImpairment:RDS/ModifyAuthenticationProcess

RDSIAMAuthDisabled

MEDIUM

DefenseImpairment:Route53Resolver/DisableOrModifyTools

DNSQueryLogsDeleted

MEDIUM

DefenseImpairment:S3/DisableOrModifyTools

S3CustomerProvidedKeysEnabled

HIGH

Execution

Attempts to run malicious code.

Finding type

Signal name

Severity

Execution:SageMaker/CommandAndScriptingInterpreter

SageMakerLifecycleConfigModified

MEDIUM

Exfiltration

Attempts to steal data from your environment.

Finding type

Signal name

Severity

Exfiltration:EC2/TransferDataToCloudAccount

AMIExternalAccess

HIGH

EBSSnapshotExternalAccess

HIGH

Exfiltration:RDS/TransferDataToCloudAccount

RDSSnapshotPubliclyShared

HIGH

Exfiltration:S3/TransferDataToCloudAccount

S3BucketPolicyExternalAccess

HIGH

Impact

Attempts to manipulate, interrupt, or destroy data and resources.

Finding type

Signal name

Severity

Impact:S3/DataDestruction

S3LifecycleRapidExpiration

MEDIUM

Impact:SES/ResourceHijacking

SESAccountSendingEnabled

LOW

SESProductionAccessEnabled

MEDIUM

Initial Access

Attempts to gain entry to your environment.

Finding type

Signal name

Severity

InitialAccess:IAM/ValidAccounts

ConsoleLoginWithoutMFA

MEDIUM

InitialAccess:RDS/ExploitPublicFacingApplication

RDSPubliclyAccessible

HIGH

Lateral Movement

Attempts to move through your environment.

Finding type

Signal name

Severity

LateralMovement:EC2/RemoteServices

EC2InstanceSSHKeyPushed

MEDIUM

Persistence

Attempts to maintain access to your environment.

Finding type

Signal name

Severity

Persistence:EC2/BootOrLogonInitializationScripts

EC2UserDataModified

HIGH

Persistence:EC2/ExternalRemoteServices

EC2SecurityGroupPublicSSH

MEDIUM

Persistence:IAM/AccountManipulation

IAMAccessKeyCreated

LOW

IAMRoleTrustPolicyModified

MEDIUM

IAMUserLoginProfileCreated

HIGH

IAMUserLoginProfileUpdated

MEDIUM

Persistence:Lambda/AccountManipulation

LambdaFunctionPublicAccess

HIGH

Persistence:Lambda/ModifyAuthenticationProcess

LambdaFunctionUrlPublicAccess

HIGH

Persistence:RolesAnywhere/AccountManipulation

RolesAnywhereTrustAnchorCreated

MEDIUM

Privilege Escalation

Attempts to gain higher-level permissions.

Finding type

Signal name

Severity

PrivilegeEscalation:IAM/AccountManipulation

AdminPolicyAttachedToRole

HIGH

AdminPolicyAttachedToUser

HIGH

BedrockServiceCredentialCreated

MEDIUM

SESFullAccessPolicyAttachedToRole

MEDIUM

SESFullAccessPolicyAttachedToUser

MEDIUM

Resource Development

Attempts to establish resources for future attacks.

Finding type

Signal name

Severity

ResourceDevelopment:SES/CompromiseAccounts

SESDomainIdentityVerified

MEDIUM