| Folder |
Scheduled Search Name (prefixed with gis_benchmarks) |
Description |
| Attack Surface Queries |
Attack Surface: Create,Delete,Update |
A total number of create, update and delete eventNames during a time period. This represents the velocity dimension for cohorting. |
| Attack Surface Queries |
Attack Surface: EC2,Redshift,S3 |
A total number of EC2, Redshift, and S3 resources during a time period. This represents the volume dimension for cohorting. |
| Attack Surface Queries |
Attack Surface: IAM,KMS,Lambda,RDS |
A total number of IAM, KMS, Lambda, and RDS resources during a time period. This represents the volume dimension for cohorting. |
| Attack Surface Queries |
Attack Surface: Service |
A total number of distinct AWS services in use during a time period. This represents the variety dimension for cohorting. |
| Event Priority Computation Query |
Event_Priority_Computation |
Compute event priority and saves to a file called "/shared/CloudTrailGIS/EventPriority". |
| Event Resource Count Queries |
CloudTrail_DisableEvents,EncryptWithNewKey_CountEventResources |
Counts the number of trails affected by signals related to disabling trails or encrypting them with a new key. |
| Event Resource Count Queries |
EC2_AuthorizeSecurityGroupIngressToPublic_CountEventResources |
Counts the number of EC2 security groups affected by signals related to allowing public ingress. |
| Event Resource Count Queries |
EC2_DescribeInstanceUserData_CountEventResources |
Counts the number of EC2 instances affected by signals describing EC2 instance metadata. |
| Event Resource Count Queries |
EC2_DisableTerminationProtectionOrListInstances_CountEventResources |
Counts the number of EC2 instances affected by signals describing EC2 instances or disabling Termination Protection. |
| Event Resource Count Queries |
EC2_ListSecurityGroups_ListImage_CountEventResources |
Counts the number of resources affected by signals describing EC2 security groups or describing AMIs. |
| Event Resource Count Queries |
EC2_TrafficMirroringOrDescribeRouteTables_CountEventResources |
Counts the number of resources affected by signals describing route tables or traffic mirroring. |
| Event Resource Count Queries |
IAM_AddUserToGroup,CompromisedUserOrKeys_CountEventResources |
Counts the number of IAM resources affected by signals related to compromised credentials or group membership changes. |
| Event Resource Count Queries |
IAM_AttachPutRoleOrGroupOrUserPolicy_CountEventResources |
Counts the number of IAM resources affected by signals related to IAM policy assignment. |
| Event Resource Count Queries |
IAM_ConsoleLoginsOrNoMfa_CountEventResources |
Count of IAM resources affected by console logins with and without multi-factor authentication. |
| Event Resource Count Queries |
IAM_CreateUpdatePolicy_CountEventResources |
Counts the number of IAM resources affected by signals related to IAM policy changes. |
| Event Resource Count Queries |
IAM_TooManyAccessDenied_CountEventResources |
Counts IAM resources affected by access denied errors. |
| Event Resource Count Queries |
IAM_UpdateAssumeRolePolicy_CountEventResources |
Counts IAM resources affected by IAM Assume Role policy changes. |
| Event Resource Count Queries |
Lambda_ExcessPermissions_CountEventResources |
Counts Lambda resources related to privileged use of functions. |
| Event Resource Count Queries |
Lambda_InteractWithIam_CountEventResources |
Counts Lambda resources that interact with IAM for any reason. |
| Event Resource Count Queries |
RDS_ModifySecurityGroup_CountEventResources |
Counts RDS resources affected by security group changes. |
| Event Resource Count Queries |
RDS_ModifyingAdminPwd,RestoreFromBackup_CountEventResources |
Counts RDS resources affected by modifying admin password or restores from backup. |
| Event Resource Count Queries |
Redshift_DisableEncryption,DisableAccessLogging_CountEventResources |
Counts Redshift resources affected by disabling encryption or Access Logging signals. |
| Event Resource Count Queries |
Redshift_DisableSSL_CountEventResources |
Counts Redshift resources affected by disabling SSL. |
| Event Resource Count Queries |
S3_AccessDeniedOrBucketConfigChecksFromPublicIp_CountEventResources |
Counts S3 buckets affected by access denied errors or configuration checks from public IP addresses. |
| Event Resource Count Queries |
S3_CrudBucketsFromPublicIp_CountEventResources |
Counts S3 buckets affected by Create, Update or Delete actions from public IP addresses. |
| Event Resource Count Queries |
S3_DisableMfaDeleteOrBucketVersionioningOrAccessLogging_CountEventResources |
Counts S3 buckets affected by disabling MFA delete, bucket versioning or access logging. |
| Event Resource Count Queries |
S3_EnablePublicAccess_CountEventResources |
Counts S3 buckets affected by public ingress risk. |
| Notable Event Count Queries |
Aggregate_Event_Count_to_Main_Index |
Merge results of many scheduled searches into a single index. |
| Notable Event Count Queries |
CloudTrail_DisableGlobalEventsOrDisableLogOrEncryptWithNewKey |
Counts the number of events related to disabling trail configurations or encrypting them with a new key. |
| Notable Event Count Queries |
CloudTrail_DisableTrails |
Counts the number of events related to disabling trails. |
| Notable Event Count Queries |
EC2_DescribeInstanceUserData |
Counts the number of events related to describing EC2 instance metadata. |
| Notable Event Count Queries |
EC2_Events |
Counts events related to DisableTerminationProtection, DescribeRouteTables, AuthorizeSecurityGroupIngressToPublic, ListAMIs, ListInstances, ListSecurityGroups, TrafficMirroring. |
| Notable Event Count Queries |
IAM_ConsoleLoginsNoMfa |
Count of console logins without multi-factor authentication. |
| Notable Event Count Queries |
IAM_Events |
Counts IAM events related to AttachPutUserPolicy, AttachPutRolePolicy, AttachPutGroupPolicy, AddUserToGroup, CompromisedUserOrKeys, CreateUpdatePolicy, ConsoleLoginFailureWithHiddenResponse, ConsoleLoginsTotal, UpdateAssumeRolePolicy. |
| Notable Event Count Queries |
IAM_TooManyAccessDenied |
Counts IAM events related to access denied errors. |
| Notable Event Count Queries |
Lambda_ExcessPermissionsOrInteractWithIam |
Counts Lambda events related to any IAM interaction or privileged use of functions |
| Notable Event Count Queries |
RDS_ModifyingAdminPassword |
Counts events related to change of admin passwords for RDS resources. |
| Notable Event Count Queries |
RDS_RestoreFromBackupOrModifySecGroup |
Counts events related to restore from backup or security group changes. |
| Notable Event Count Queries |
Redshift_DisableEncryption |
Counts Redshift events related to disabling encryption. |
| Notable Event Count Queries |
Redshift_DisableSSLOrDisableAccesslogging |
Counts Redshift events related to disabling encryption or SSL. |
| Notable Event Count Queries |
S3_AccessDeniedOrBucketConfigChecksFromPublicIp |
Counts S3 events related to access denied errors or configuration checks from public IP addresses. |
| Notable Event Count Queries |
S3_CrudBucketsFromPublicIp_CountEventResources |
Counts S3 events related to Create, Update or Delete actions from public IP addresses. |
| Notable Event Count Queries |
S3_DisableMfaDeleteOrBucketVersionioningOrAccessLogging |
Counts S3 events related to disabling MFA delete, bucket versioning or access logging. |
| Notable Event Count Queries |
S3_EnablePublicAccess |
Counts S3 events related to enabling public ingress. |
| Notable Event Count Queries |
S3_ListBuckets |
Counts S3 events related to listing buckets. |