AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules

Identifies when EC2 network ACL entries are created in AWS via CloudTrail.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
jamesc-grafana (SigmaHQ), DRL 1.1
Published
2024-07-11
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies AWS CloudTrail events where a new network ACL entry is created (CreateNetworkAclEntry) for EC2. Adding ACL rules can broaden network reachability and potentially open new paths for inbound or outbound traffic, making it important for spotting configuration changes. It relies on CloudTrail telemetry recording EC2 API calls with event source and event name.

Related detections4 linkedT1686.001 — drag to rearrange
AWS CloudTrail: CreateRoute Adds New Network Route to a Route Table
Azure Network Firewall Policy Modified or Deleted via Activity Logs
Azure Firewall Rule Collection Modified or Deleted via Activity Logs
Azure Firewall Created, Modified, or Deleted via Activity Log
AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Pivot detection · T1686.001 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.