AWS CloudTrail: CreateFunctionUrlConfig Indicates Lambda Function URL Added

Flags when a Lambda Function URL configuration is created via the CreateFunctionUrlConfig API call.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Ivan Saakov (SigmaHQ), DRL 1.1
Published
2024-12-19
Updated
2026-07-31

What it detects

This rule identifies CloudTrail events where a user creates a Lambda function URL configuration. Exposing a function via a public URL can enable unintended access paths and may allow an attacker to leverage the Lambda function’s associated permissions when combined with other conditions. The detection relies on AWS CloudTrail telemetry capturing eventSource=lambda.amazonaws.com and eventName=CreateFunctionUrlConfig.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.