AWS ElastiCache Cache Security Group Created via CloudTrail
Flags CloudTrail events indicating a new ElastiCache cache security group was created.
FreeUnreviewedSigmalowv1
aws-elasticache-cache-security-group-created-via-cloudtrail-4ae68615
title: AWS ElastiCache Cache Security Group Created via CloudTrail
id: 2050e2bc-d5cc-4f8f-83c8-53f2639dbab2
status: test
description: This rule identifies CloudTrail events where an ElastiCache cache security group is created. Attackers may use new security groups to change network access controls for managed Redis/Memcached resources, enabling persistence or later exploitation. The detection relies on AWS CloudTrail fields matching eventSource elasticache.amazonaws.com and eventName CreateCacheSecurityGroup.
references:
- https://github.com/elastic/detection-rules/blob/598f3d7e0a63221c0703ad9a0ea7e22e7bc5961e/rules/integrations/aws/persistence_elasticache_security_group_creation.toml
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_created.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-07-24
modified: 2022-10-09
tags:
- attack.persistence
- attack.t1136
- attack.t1136.003
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: elasticache.amazonaws.com
eventName: CreateCacheSecurityGroup
condition: selection
falsepositives:
- A ElastiCache security group may be created by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security group creations from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 4ae68615-866f-4304-b24b-ba048dfa5ca7
type: derived
What it detects
This rule identifies CloudTrail events where an ElastiCache cache security group is created. Attackers may use new security groups to change network access controls for managed Redis/Memcached resources, enabling persistence or later exploitation. The detection relies on AWS CloudTrail fields matching eventSource elasticache.amazonaws.com and eventName CreateCacheSecurityGroup.
Known false positives
- A ElastiCache security group may be created by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security group creations from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.