AWS CloudTrail: ElastiCache Cache Security Group Created

Flags CloudTrail events indicating a new ElastiCache cache security group was created.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-24
Updated
2026-07-31
title: "AWS CloudTrail: ElastiCache Cache Security Group Created"
id: 2050e2bc-d5cc-4f8f-83c8-53f2639dbab2
status: test
description: This rule identifies AWS CloudTrail events where an ElastiCache cache security group is created via the CreateCacheSecurityGroup API. Attackers or administrators could use this to alter network access boundaries for ElastiCache resources, potentially enabling unwanted connectivity. Detection relies on CloudTrail telemetry with eventSource set to elasticache.amazonaws.com and eventName set to CreateCacheSecurityGroup.
references:
  - https://github.com/elastic/detection-rules/blob/598f3d7e0a63221c0703ad9a0ea7e22e7bc5961e/rules/integrations/aws/persistence_elasticache_security_group_creation.toml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_created.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-07-24
modified: 2022-10-09
tags:
  - attack.persistence
  - attack.t1136
  - attack.t1136.003
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: elasticache.amazonaws.com
    eventName: CreateCacheSecurityGroup
  condition: selection
falsepositives:
  - A ElastiCache security group may be created by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security group creations from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
  - id: 4ae68615-866f-4304-b24b-ba048dfa5ca7
    type: derived